CVE Database

53300+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21256
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21255
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21249
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21242
5.9 MEDIUM

Windows Kerberos Information Disclosure Vulnerability

Jan 14, 2025
CVE-2025-21232
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21229
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21228
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21227
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21226
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21225
5.9 MEDIUM

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

Jan 14, 2025
CVE-2025-21219
4.3 MEDIUM

MapUrlToZone Security Feature Bypass Vulnerability

Jan 14, 2025
CVE-2025-21217
6.5 MEDIUM

Windows NTLM Spoofing Vulnerability

Jan 14, 2025
CVE-2025-21215
4.6 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Jan 14, 2025
CVE-2025-21214
4.2 MEDIUM

Windows BitLocker Information Disclosure Vulnerability

Jan 14, 2025
CVE-2025-21213
4.6 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Jan 14, 2025
CVE-2025-21211
6.8 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Jan 14, 2025
CVE-2025-21210
4.2 MEDIUM

Windows BitLocker Information Disclosure Vulnerability

Jan 14, 2025
CVE-2025-21202
6.1 MEDIUM

Windows Recovery Environment Agent Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21193
6.5 MEDIUM

Active Directory Federation Server Spoofing Vulnerability

Jan 14, 2025
CVE-2025-21189
4.3 MEDIUM

MapUrlToZone Security Feature Bypass Vulnerability

Jan 14, 2025
CVE-2024-12747
5.6 MEDIUM

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic …

Jan 14, 2025
CVE-2024-12088
6.5 MEDIUM

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from …

Jan 14, 2025
CVE-2024-12087
6.5 MEDIUM

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can …

Jan 14, 2025
CVE-2024-12086
6.1 MEDIUM

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue …

Jan 14, 2025
CVE-2025-23081
6.1 MEDIUM

Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows …

Jan 14, 2025
CVE-2025-23080
5.3 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - OpenBadges Extension allows Cross-Site Scripting (XSS).This issue …

Jan 14, 2025
CVE-2025-0463
6.3 MEDIUM

A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified as critical. Affected is an unknown function …

Jan 14, 2025
CVE-2025-0462
6.3 MEDIUM

A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as critical. This issue affects some unknown processing of …

Jan 14, 2025
CVE-2024-53563
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary web scripts or HTML via injecting …

Jan 14, 2025
CVE-2024-52898
6.2 MEDIUM

IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a detailed …

Jan 14, 2025
CVE-2024-45627
5.9 MEDIUM

In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module …

Jan 14, 2025
CVE-2025-0461
4.3 MEDIUM

A vulnerability has been found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as problematic. This vulnerability affects unknown code of …

Jan 14, 2025
CVE-2025-0459
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in libretro RetroArch up to 1.19.1 on Windows. Affected by this issue is some unknown …

Jan 14, 2025
CVE-2025-0458
4.3 MEDIUM

A vulnerability classified as problematic was found in Virtual Computer Vysual RH Solution 2024.12.1. Affected by this vulnerability is an unknown functionality of the file …

Jan 14, 2025
CVE-2024-55000
5.4 MEDIUM

Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php.

Jan 14, 2025
CVE-2024-39773
5.3 MEDIUM

An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive …

Jan 14, 2025
CVE-2024-56497
6.7 MEDIUM

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 …

Jan 14, 2025
CVE-2024-54021
6.5 MEDIUM

An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 may …

Jan 14, 2025
CVE-2024-52969
4.1 MEDIUM

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1.0, version 7.0.3 …

Jan 14, 2025
CVE-2024-48893
6.8 MEDIUM

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to …

Jan 14, 2025
CVE-2024-48890
6.6 MEDIUM

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may …

Jan 14, 2025
CVE-2024-47566
5.1 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a …

Jan 14, 2025
CVE-2024-46666
5.3 MEDIUM

An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all versions, 7.0 all versions, 6.4 …

Jan 14, 2025
CVE-2024-46664
5.5 MEDIUM

A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying …

Jan 14, 2025
CVE-2024-45326
4.3 MEDIUM

An Improper Access Control vulnerability [CWE-284] vulnerability in Fortinet FortiDeceptor 6.0.0, FortiDeceptor 5.3 all versions, FortiDeceptor 5.2 all versions, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 …

Jan 14, 2025
CVE-2024-40587
6.7 MEDIUM

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before …

Jan 14, 2025
CVE-2024-36510
5.3 MEDIUM

An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 …

Jan 14, 2025
CVE-2024-36504
6.5 MEDIUM

An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions …

Jan 14, 2025
CVE-2024-35278
4.3 MEDIUM

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may …

Jan 14, 2025
CVE-2024-35276
5.6 MEDIUM

A stack-based buffer overflow in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager versions 7.4.0 through 7.4.3, …

Jan 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.