CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-2875
7.5 HIGH

CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of confidentiality when an unauthenticated attacker manipulates controller’s …

May 14, 2025
CVE-2024-8988
5.3 MEDIUM

The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.6.0 via the …

May 14, 2025
CVE-2024-13940
5.5 MEDIUM

The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.7 via the form webhook …

May 14, 2025
CVE-2025-0020

Rejected reason: “This CVE ID is Rejected and will not be used. As the CNA of record ESRI has rejected this CVE as it is …

May 14, 2025
CVE-2024-52290
6.3 MEDIUM

LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version 2.1.0 user with rights to modificate …

May 14, 2025
CVE-2025-47899

Rejected reason: Not used

May 14, 2025
CVE-2025-47898

Rejected reason: Not used

May 14, 2025
CVE-2025-47897

Rejected reason: Not used

May 14, 2025
CVE-2025-47896

Rejected reason: Not used

May 14, 2025
CVE-2025-47895

Rejected reason: Not used

May 14, 2025
CVE-2025-47894

Rejected reason: Not used

May 14, 2025
CVE-2025-47893

Rejected reason: Not used

May 14, 2025
CVE-2025-47892

Rejected reason: Not used

May 14, 2025
CVE-2025-47891

Rejected reason: Not used

May 14, 2025
CVE-2025-4520
5.4 MEDIUM

The Uncanny Automator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions …

May 14, 2025
CVE-2025-3623
9.1 CRITICAL

The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input …

May 14, 2025
CVE-2025-4574
6.5 MEDIUM

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could …

May 13, 2025
CVE-2025-47905
5.4 MEDIUM

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF …

May 13, 2025
CVE-2025-26646
8.0 HIGH

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over …

May 13, 2025
CVE-2025-43572
7.8 HIGH

Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current …

May 13, 2025
CVE-2025-43571
7.8 HIGH

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-43570
7.8 HIGH

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-43569
7.8 HIGH

Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 13, 2025
CVE-2025-43568
7.8 HIGH

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-43567
9.3 CRITICAL

Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious …

May 13, 2025
CVE-2025-43566
6.8 MEDIUM

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could …

May 13, 2025
CVE-2025-43565
8.4 HIGH

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of …

May 13, 2025
CVE-2025-43564
9.1 CRITICAL

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged …

May 13, 2025
CVE-2025-43563
9.1 CRITICAL

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged …

May 13, 2025
CVE-2025-43562
9.1 CRITICAL

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability …

May 13, 2025
CVE-2025-43561
9.1 CRITICAL

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …

May 13, 2025
CVE-2025-43560
9.1 CRITICAL

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-43559
9.1 CRITICAL

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-43554
7.8 HIGH

Substance3D - Modeler versions 1.21.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 13, 2025
CVE-2025-43553
7.8 HIGH

Substance3D - Modeler versions 1.21.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the …

May 13, 2025
CVE-2025-43551
5.5 MEDIUM

Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

May 13, 2025
CVE-2025-43549
7.8 HIGH

Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-43548
7.8 HIGH

Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current …

May 13, 2025
CVE-2025-30316
5.4 MEDIUM

Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to …

May 13, 2025
CVE-2025-30315
6.1 MEDIUM

Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious …

May 13, 2025
CVE-2025-30314
6.1 MEDIUM

Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious …

May 13, 2025
CVE-2025-24495
5.6 MEDIUM

Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an authenticated user to potentially enable information disclosure …

May 13, 2025
CVE-2025-24308
7.5 HIGH

Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privileged user to potentially enable escalation …

May 13, 2025
CVE-2025-23233
3.5 LOW

Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via …

May 13, 2025
CVE-2025-22895
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially …

May 13, 2025
CVE-2025-22892
6.5 MEDIUM

Uncontrolled resource consumption for some OpenVINO™ model server software maintained by Intel(R) before version 2024.4 may allow an unauthenticated user to potentially enable denial of …

May 13, 2025
CVE-2025-22848
3.5 LOW

Improper conditions check for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable denial of service via …

May 13, 2025
CVE-2025-22844
4.3 MEDIUM

Improper access control for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an unauthenticated user to potentially enable information disclosure via adjacent …

May 13, 2025
CVE-2025-22843
7.8 HIGH

Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable escalation of privilege via …

May 13, 2025
CVE-2025-22448
6.1 MEDIUM

Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow an authenticated user to potentially enable denial of service via …

May 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.