CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-31352
6.0 MEDIUM

A bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in loss of guest private data.

Feb 11, 2025
CVE-2022-37660
6.5 MEDIUM

In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public keys with another …

Feb 11, 2025
CVE-2024-57777
5.1 MEDIUM

Directory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive information

Feb 11, 2025
CVE-2024-57241
6.5 MEDIUM

Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in …

Feb 11, 2025
CVE-2024-55212
6.5 MEDIUM

DNNGo xBlog v6.5.0 was discovered to contain a SQL injection vulnerability via the Categorys parameter at /DNNGo_xBlog/Resource_Service.aspx.

Feb 11, 2025
CVE-2023-20582
5.3 MEDIUM

Improper handling of invalid nested page table entries in the IOMMU may allow a privileged attacker to induce page table entry (PTE) faults to bypass …

Feb 11, 2025
CVE-2023-20515
5.7 MEDIUM

Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory, potentially leading to loss of …

Feb 11, 2025
CVE-2025-25529
5.1 MEDIUM

Buffer overflow vulnerability in Digital China DCBC Gateway 200-2.1.1 due to the lack of length verification, which is related to the configuration of static NAT …

Feb 11, 2025
CVE-2025-25528
5.1 MEDIUM

Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, …

Feb 11, 2025
CVE-2025-25527
5.1 MEDIUM

Buffer overflow vulnerability in Ruijie RG-NBR2600S Gateway 10.3(4b12) due to the lack of length verification, which is related to the configuration of source address NAT …

Feb 11, 2025
CVE-2025-25526
5.1 MEDIUM

Buffer overflow vulnerability in Mercury MIPC552W Camera v1.0 due to the lack of length verification, which is related to the configuration of the PPTP server. …

Feb 11, 2025
CVE-2025-25525
5.1 MEDIUM

Buffer overflow vulnerability in H3C FA3010L access points SWFA1B0V100R005 due to the lack of length verification, which is related to the setting of firewall rules. …

Feb 11, 2025
CVE-2024-12833
6.1 MEDIUM

Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Paessler PRTG Network …

Feb 11, 2025
CVE-2025-25524
5.1 MEDIUM

Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. …

Feb 11, 2025
CVE-2025-25523
5.9 MEDIUM

Buffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related to the mobile access point …

Feb 11, 2025
CVE-2025-25202
6.5 MEDIUM

Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have …

Feb 11, 2025
CVE-2022-35202
5.1 MEDIUM

A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private keys used …

Feb 11, 2025
CVE-2025-24437
5.4 MEDIUM

Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24436
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24435
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A …

Feb 11, 2025
CVE-2025-24428
5.4 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Feb 11, 2025
CVE-2025-24427
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24426
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24425
5.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Business Logic Error vulnerability that could result in a security feature …

Feb 11, 2025
CVE-2025-24424
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24423
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A …

Feb 11, 2025
CVE-2025-24422
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24421
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24420
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24419
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24408
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged …

Feb 11, 2025
CVE-2025-21377
6.5 MEDIUM

NTLM Hash Disclosure Spoofing Vulnerability

Feb 11, 2025
CVE-2025-21352
6.5 MEDIUM

Internet Connection Sharing (ICS) Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21350
5.9 MEDIUM

Windows Kerberos Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21349
6.8 MEDIUM

Windows Remote Desktop Configuration Service Tampering Vulnerability

Feb 11, 2025
CVE-2025-21347
6.0 MEDIUM

Windows Deployment Services Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21259
5.3 MEDIUM

Microsoft Outlook Spoofing Vulnerability

Feb 11, 2025
CVE-2025-21254
6.5 MEDIUM

Internet Connection Sharing (ICS) Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21216
6.5 MEDIUM

Internet Connection Sharing (ICS) Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21212
6.5 MEDIUM

Internet Connection Sharing (ICS) Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21188
6.0 MEDIUM

Azure Network Watcher VM Extension Elevation of Privilege Vulnerability

Feb 11, 2025
CVE-2025-21179
4.8 MEDIUM

DHCP Client Service Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21162
5.5 MEDIUM

Photoshop Elements versions 2025.0 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege …

Feb 11, 2025
CVE-2025-21155
5.5 MEDIUM

Substance3D - Stager versions 3.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Feb 11, 2025
CVE-2019-15002
4.3 MEDIUM

An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an …

Feb 11, 2025
CVE-2025-21126
5.5 MEDIUM

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service condition. An attacker …

Feb 11, 2025
CVE-2025-21125
5.5 MEDIUM

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Feb 11, 2025
CVE-2025-21124
5.5 MEDIUM

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 11, 2025
CVE-2024-52968
6.7 MEDIUM

An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.

Feb 11, 2025
CVE-2024-50569
6.6 MEDIUM

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allows attacker to execute unauthorized …

Feb 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.