CVE Database

46542+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21235
7.8 HIGH

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21234
7.8 HIGH

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21233
8.8 HIGH

Windows Telephony Service Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21231
7.5 HIGH

IP Helper Denial of Service Vulnerability

Jan 14, 2025
CVE-2025-21230
7.5 HIGH

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

Jan 14, 2025
CVE-2025-21224
8.1 HIGH

Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21223
8.8 HIGH

Windows Telephony Service Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21220
7.5 HIGH

Microsoft Message Queuing Information Disclosure Vulnerability

Jan 14, 2025
CVE-2025-21218
7.5 HIGH

Windows Kerberos Denial of Service Vulnerability

Jan 14, 2025
CVE-2025-21207
7.5 HIGH

Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability

Jan 14, 2025
CVE-2025-21187
7.8 HIGH

Microsoft Power Automate Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21186
7.8 HIGH

Microsoft Access Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21178
8.8 HIGH

Visual Studio Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21176
8.8 HIGH

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21173
7.3 HIGH

.NET Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21172
7.5 HIGH

.NET and Visual Studio Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21171
7.5 HIGH

.NET Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-0465
7.3 HIGH

A vulnerability was found in AquilaCMS 1.412.13. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/v2/categories. …

Jan 14, 2025
CVE-2024-13172
7.8 HIGH

Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve …

Jan 14, 2025
CVE-2024-13171
7.8 HIGH

Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve …

Jan 14, 2025
CVE-2024-13170
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13169
7.8 HIGH

An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate …

Jan 14, 2025
CVE-2024-13168
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13167
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13166
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13165
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13164
7.8 HIGH

An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate …

Jan 14, 2025
CVE-2024-13163
7.8 HIGH

Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to …

Jan 14, 2025
CVE-2024-13162
7.2 HIGH

SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges …

Jan 14, 2025
CVE-2024-13158
7.2 HIGH

An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker …

Jan 14, 2025
CVE-2024-12085
7.5 HIGH

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length …

Jan 14, 2025
CVE-2024-53561
8.7 HIGH

A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary code via a crafted request.

Jan 14, 2025
CVE-2024-13181
7.3 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.

Jan 14, 2025
CVE-2024-13180
7.5 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.

Jan 14, 2025
CVE-2024-13179
7.3 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.

Jan 14, 2025
CVE-2024-10630
7.8 HIGH

A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.

Jan 14, 2025
CVE-2025-22984
7.5 HIGH

An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.

Jan 14, 2025
CVE-2025-22983
7.5 HIGH

An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.

Jan 14, 2025
CVE-2025-0460
7.3 HIGH

A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the …

Jan 14, 2025
CVE-2024-42444
7.5 HIGH

APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful exploitation of this vulnerability may lead …

Jan 14, 2025
CVE-2024-7344
8.2 HIGH

Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.

Jan 14, 2025
CVE-2024-50566
7.2 HIGH

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 …

Jan 14, 2025
CVE-2024-48884
7.5 HIGH

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud …

Jan 14, 2025
CVE-2024-47571
8.1 HIGH

An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via …

Jan 14, 2025
CVE-2024-46670
7.5 HIGH

An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE …

Jan 14, 2025
CVE-2024-46668
7.5 HIGH

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and …

Jan 14, 2025
CVE-2024-46667
7.5 HIGH

A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 …

Jan 14, 2025
CVE-2024-36512
7.2 HIGH

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 …

Jan 14, 2025
CVE-2024-35277
8.6 HIGH

A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 …

Jan 14, 2025
CVE-2024-35273
7.2 HIGH

A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http …

Jan 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.