CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43573
7.8 HIGH

Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the …

Jun 10, 2025
CVE-2025-43550
7.8 HIGH

Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the …

Jun 10, 2025
CVE-2025-30327
7.8 HIGH

InCopy versions 20.2, 19.5.3 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context …

Jun 10, 2025
CVE-2025-5971
6.3 MEDIUM

A vulnerability was found in code-projects School Fees Payment System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jun 10, 2025
CVE-2025-5943
8.8 HIGH

MicroDicom DICOM Viewer suffers from an out-of-bounds write vulnerability. Remote attackers are able to exploit this issue to potentially execute arbitrary code on affected installations …

Jun 10, 2025
CVE-2025-43588
7.8 HIGH

Substance3D - Sampler versions 5.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jun 10, 2025
CVE-2025-43581
7.8 HIGH

Substance3D - Sampler versions 5.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jun 10, 2025
CVE-2025-36580
6.1 MEDIUM

Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged …

Jun 10, 2025
CVE-2025-36578
6.8 MEDIUM

Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this …

Jun 10, 2025
CVE-2025-36577
6.1 MEDIUM

Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged …

Jun 10, 2025
CVE-2025-36576
2.7 LOW

Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) vulnerability. A high privileged attacker with remote access could potentially …

Jun 10, 2025
CVE-2025-36575
7.5 HIGH

Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability. An unauthenticated attacker with remote access …

Jun 10, 2025
CVE-2025-36574
8.2 HIGH

Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this …

Jun 10, 2025
CVE-2025-2884
6.6 MEDIUM

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's …

Jun 10, 2025
CVE-2025-2474
9.8 CRITICAL

Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition …

Jun 10, 2025
CVE-2025-0052

Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service.

Jun 10, 2025
CVE-2025-0051

Improper input validation performed during the authentication process of FlashArray could lead to a system Denial of Service.

Jun 10, 2025
CVE-2024-37396
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting …

Jun 10, 2025
CVE-2024-37395
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by …

Jun 10, 2025
CVE-2024-37394
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting …

Jun 10, 2025
CVE-2025-5970
2.4 LOW

A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the …

Jun 10, 2025
CVE-2025-5969
8.8 HIGH

A vulnerability has been found in D-Link DIR-632 FW103B08 and classified as critical. Affected by this vulnerability is the function FUN_00425fd8 of the file /biurl_grou …

Jun 10, 2025
CVE-2025-47977
8.2 HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network.

Jun 10, 2025
CVE-2025-47969
4.4 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-47968
7.8 HIGH

Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-47962
7.8 HIGH

Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-47957
8.4 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47956
5.5 MEDIUM

External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

Jun 10, 2025
CVE-2025-47955
7.8 HIGH

Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-47953
8.4 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47176
7.8 HIGH

'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47175
7.8 HIGH

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47174
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47173
7.8 HIGH

Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47172
8.8 HIGH

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a …

Jun 10, 2025
CVE-2025-47171
6.7 MEDIUM

Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47170
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47169
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47168
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47167
8.4 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47166
8.8 HIGH

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Jun 10, 2025
CVE-2025-47165
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47164
8.4 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47163
8.8 HIGH

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Jun 10, 2025
CVE-2025-47162
8.4 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Jun 10, 2025
CVE-2025-47160
5.4 MEDIUM

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

Jun 10, 2025
CVE-2025-47108
7.8 HIGH

Substance3D - Painter versions 11.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jun 10, 2025
CVE-2025-47106
5.5 MEDIUM

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jun 10, 2025
CVE-2025-47105
5.5 MEDIUM

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jun 10, 2025
CVE-2025-47104
5.5 MEDIUM

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jun 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.