CVE Database

117544+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-29968
6.5 MEDIUM

Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.

May 13, 2025
CVE-2025-29967
8.8 HIGH

Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

May 13, 2025
CVE-2025-29966
8.8 HIGH

Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.

May 13, 2025
CVE-2025-29964
8.8 HIGH

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

May 13, 2025
CVE-2025-29963
8.8 HIGH

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

May 13, 2025
CVE-2025-29962
8.8 HIGH

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

May 13, 2025
CVE-2025-29961
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29960
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29959
6.5 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29958
6.5 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29957
6.2 MEDIUM

Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.

May 13, 2025
CVE-2025-29956
5.4 MEDIUM

Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29955
6.2 MEDIUM

Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.

May 13, 2025
CVE-2025-29954
5.9 MEDIUM

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

May 13, 2025
CVE-2025-29842
7.5 HIGH

Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network.

May 13, 2025
CVE-2025-29841
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally.

May 13, 2025
CVE-2025-29840
8.8 HIGH

Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

May 13, 2025
CVE-2025-29839
4.0 MEDIUM

Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.

May 13, 2025
CVE-2025-29838
7.4 HIGH

Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally.

May 13, 2025
CVE-2025-29837
5.5 MEDIUM

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.

May 13, 2025
CVE-2025-29836
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29835
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29833
7.7 HIGH

Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.

May 13, 2025
CVE-2025-29832
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29831
7.5 HIGH

Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

May 13, 2025
CVE-2025-29830
6.5 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

May 13, 2025
CVE-2025-29829
5.5 MEDIUM

Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.

May 13, 2025
CVE-2025-29826
7.3 HIGH

Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

May 13, 2025
CVE-2025-27488
6.7 MEDIUM

Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.

May 13, 2025
CVE-2025-27468
7.0 HIGH

Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

May 13, 2025
CVE-2025-26685
6.5 MEDIUM

Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

May 13, 2025
CVE-2025-26684
6.7 MEDIUM

External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

May 13, 2025
CVE-2025-26677
7.5 HIGH

Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

May 13, 2025
CVE-2025-24063
7.8 HIGH

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

May 13, 2025
CVE-2025-21264
7.1 HIGH

Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

May 13, 2025
CVE-2025-0035
7.3 HIGH

Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution.

May 13, 2025
CVE-2024-6364
6.4 MEDIUM

A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled attacker with both physical access to …

May 13, 2025
CVE-2024-36339
7.3 HIGH

A DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

May 13, 2025
CVE-2024-36321
7.3 HIGH

Unquoted search path within AIM-T Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution.

May 13, 2025
CVE-2024-21960
7.3 HIGH

Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code …

May 13, 2025
CVE-2025-4428
7.2 HIGH KEV

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via …

May 13, 2025
CVE-2025-4427
5.3 MEDIUM KEV

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via …

May 13, 2025
CVE-2025-47278

Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configuration was handled resulted in the last …

May 13, 2025
CVE-2025-47276
7.5 HIGH

Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating systems (OS). Prior to version 1.2.0, Actualizer uses …

May 13, 2025
CVE-2025-47204
6.1 MEDIUM

An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a …

May 13, 2025
CVE-2025-46721
6.1 MEDIUM

nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 allows an attacker who controls content on the …

May 13, 2025
CVE-2025-45858
9.8 CRITICAL

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.

May 13, 2025
CVE-2025-45857
9.8 CRITICAL

EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.

May 13, 2025
CVE-2025-31493
9.1 CRITICAL

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `collection()` …

May 13, 2025
CVE-2025-30207
7.5 HIGH

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that use PHP's built-in …

May 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.