CVE Database

53059+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27186
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-27185
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Apr 8, 2025
CVE-2025-27184
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-26681
6.7 MEDIUM

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26676
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-26672
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-26667
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a …

Apr 8, 2025
CVE-2025-26664
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-26651
6.5 MEDIUM

Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26644
5.1 MEDIUM

Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.

Apr 8, 2025
CVE-2025-26637
6.8 MEDIUM

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Apr 8, 2025
CVE-2025-26635
6.5 MEDIUM

Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.

Apr 8, 2025
CVE-2025-25002
6.8 MEDIUM

Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.

Apr 8, 2025
CVE-2025-21203
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-21197
6.5 MEDIUM

Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to …

Apr 8, 2025
CVE-2025-32279
4.3 MEDIUM

Missing Authorization vulnerability in Shahjada Live Forms liveforms.This issue affects Live Forms: from n/a through <= 4.8.5.

Apr 8, 2025
CVE-2025-32211
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet Broadstreet Ads broadstreet allows Stored XSS.This issue affects Broadstreet Ads: from n/a …

Apr 8, 2025
CVE-2025-32164
6.5 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadList m1downloadlist allows Retrieve Embedded Sensitive Data.This issue affects m1.DownloadList: from n/a …

Apr 8, 2025
CVE-2025-30671
6.5 MEDIUM

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Apr 8, 2025
CVE-2025-30670
6.5 MEDIUM

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Apr 8, 2025
CVE-2025-27442
4.6 MEDIUM

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

Apr 8, 2025
CVE-2025-27441
4.6 MEDIUM

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

Apr 8, 2025
CVE-2025-27085
4.9 MEDIUM

Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote …

Apr 8, 2025
CVE-2025-27084
5.4 MEDIUM

A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting …

Apr 8, 2025
CVE-2024-52981
4.9 MEDIUM

An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.

Apr 8, 2025
CVE-2024-52980
6.5 MEDIUM

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. …

Apr 8, 2025
CVE-2024-52974
6.5 MEDIUM

An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful attack …

Apr 8, 2025
CVE-2025-27079
6.0 MEDIUM

A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to …

Apr 8, 2025
CVE-2025-27078
6.5 MEDIUM

A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating …

Apr 8, 2025
CVE-2025-22465
6.1 MEDIUM

Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in …

Apr 8, 2025
CVE-2025-22464
6.1 MEDIUM

An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to …

Apr 8, 2025
CVE-2025-22459
4.8 MEDIUM

Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic …

Apr 8, 2025
CVE-2025-30150
5.3 MEDIUM

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if …

Apr 8, 2025
CVE-2024-54025
6.7 MEDIUM

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator CLI before version 2.4.6 allows a …

Apr 8, 2025
CVE-2024-52962
5.3 MEDIUM

An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and …

Apr 8, 2025
CVE-2024-46671
6.2 MEDIUM

An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets …

Apr 8, 2025
CVE-2025-2876
5.3 MEDIUM

The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability check …

Apr 8, 2025
CVE-2025-2568
5.3 MEDIUM

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing …

Apr 8, 2025
CVE-2025-30166
4.8 MEDIUM

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. An HTML injection issue allows users with access to the email sending functionality to inject …

Apr 8, 2025
CVE-2025-29985
6.5 MEDIUM

Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Initialization of a Resource with an Insecure Default vulnerability in the Common Anti-Virus Agent (CAVA). An …

Apr 8, 2025
CVE-2025-3437
4.3 MEDIUM

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Apr 8, 2025
CVE-2025-2883
5.3 MEDIUM

The Accept SagePay Payments Using Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 …

Apr 8, 2025
CVE-2025-2808
5.4 MEDIUM

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all …

Apr 8, 2025
CVE-2025-3436
6.5 MEDIUM

The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'order' and 'orderby' parameters in all versions up to, …

Apr 8, 2025
CVE-2025-3433
6.1 MEDIUM

The Advanced Advertising System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.1. This is due to insufficient …

Apr 8, 2025
CVE-2025-3432
6.4 MEDIUM

The AAWP Obfuscator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-aawp-web' parameter in all versions up to, and including, 1.0 due …

Apr 8, 2025
CVE-2025-30280
5.3 MEDIUM

A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.21.0), Mendix Runtime V10.12 (All versions < V10.12.16), Mendix Runtime V10.18 (All versions …

Apr 8, 2025
CVE-2025-30000
6.7 MEDIUM

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does not properly restrict permissions of the users. …

Apr 8, 2025
CVE-2025-29999
6.7 MEDIUM

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application searches for executable files in the application folder …

Apr 8, 2025
CVE-2025-22017
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: devlink: fix xa_alloc_cyclic() error handling In case of returning 1 from xa_alloc_cyclic() (wrapping) ERR_PTR(1) will …

Apr 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.