CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-54096
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-54095
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-54094
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-54093
7.0 HIGH

Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-54092
7.8 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-54091
7.8 HIGH

Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53810
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53809
6.5 MEDIUM

Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

Sep 9, 2025
CVE-2025-53808
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53807
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53806
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-53805
7.5 HIGH

Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.

Sep 9, 2025
CVE-2025-53804
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Sep 9, 2025
CVE-2025-53803
5.5 MEDIUM

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

Sep 9, 2025
CVE-2025-53802
7.0 HIGH

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53801
7.8 HIGH

Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53800
7.8 HIGH

No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-53799
5.5 MEDIUM

Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

Sep 9, 2025
CVE-2025-53798
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-53797
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-53796
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-53348
5.3 MEDIUM

Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kalium: from n/a through <= 3.18.3.

Sep 9, 2025
CVE-2025-53340
5.3 MEDIUM

Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a through <= 6.3.6.

Sep 9, 2025
CVE-2025-53303
8.8 HIGH

Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object Injection.This issue affects ThemeMove Core: from n/a through <= 1.4.2.

Sep 9, 2025
CVE-2025-53291
5.4 MEDIUM

Missing Authorization vulnerability in spoddev2021 Spreadconnect wc-spod.This issue affects Spreadconnect: from n/a through <= 2.1.5.

Sep 9, 2025
CVE-2025-49860
5.3 MEDIUM

Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Support: from n/a through <= 1.1.0.

Sep 9, 2025
CVE-2025-49734
7.0 HIGH

Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-49692
7.8 HIGH

Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

Sep 9, 2025
CVE-2025-49430
7.2 HIGH

Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request Forgery.This issue affects Ultimate Video Player: from n/a through <= …

Sep 9, 2025
CVE-2025-48101
8.8 HIGH

Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: from n/a through 4.1.1.

Sep 9, 2025
CVE-2025-47997
6.5 MEDIUM

Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.

Sep 9, 2025
CVE-2025-47695
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in solwin Blog Designer PRO blog-designer-pro.This issue affects Blog Designer …

Sep 9, 2025
CVE-2025-47694
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in solwin Blog Designer PRO blog-designer-pro.This issue affects Blog Designer PRO: from n/a through …

Sep 9, 2025
CVE-2025-47579
9.0 CRITICAL

Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through <= 7.7.2.

Sep 9, 2025
CVE-2025-47571
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder superstorefinder-wp allows PHP Local File …

Sep 9, 2025
CVE-2025-47570
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews.This issue affects WooCommerce Photo Reviews: from n/a through …

Sep 9, 2025
CVE-2025-47569
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommerce Ultimate Gift Card woocommerce-ultimate-gift-card allows Blind SQL Injection.This issue …

Sep 9, 2025
CVE-2025-47437
6.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 7.0.1.

Sep 9, 2025
CVE-2025-39553
4.3 MEDIUM

Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 5.0.9.

Sep 9, 2025
CVE-2025-39541
6.5 MEDIUM

Missing Authorization vulnerability in Roland Murg WP Simple Booking Calendar wp-simple-booking-calendar.This issue affects WP Simple Booking Calendar: from n/a through <= 2.0.13.

Sep 9, 2025
CVE-2025-39523
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in GoodBarber GoodBarber goodbarber.This issue affects GoodBarber: from n/a through <= 1.0.26.

Sep 9, 2025
CVE-2025-32689
7.5 HIGH

Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects WP SmartPay: from n/a through <= 2.8.2.

Sep 9, 2025
CVE-2025-32688
5.4 MEDIUM

Missing Authorization vulnerability in Nebojsa Target Video Easy Publish brid-video-easy-publish.This issue affects Target Video Easy Publish: from n/a through <= 3.8.9.

Sep 9, 2025
CVE-2025-32486
9.8 CRITICAL

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.This issue affects Material Dashboard: from n/a through <= 1.4.6.

Sep 9, 2025
CVE-2025-30875
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexandre Froger WP Weixin wp-weixin allows Stored XSS.This issue affects WP Weixin: from …

Sep 9, 2025
CVE-2025-9872
8.8 HIGH

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. …

Sep 9, 2025
CVE-2025-9712
8.8 HIGH

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. …

Sep 9, 2025
CVE-2025-8712
5.4 MEDIUM

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure …

Sep 9, 2025
CVE-2025-8711
5.4 MEDIUM

CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access …

Sep 9, 2025
CVE-2025-55148
7.6 HIGH

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure …

Sep 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.