CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-32774

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32773

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32772

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32771

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32770

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32769

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32768

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32767

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32765

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32764

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32763

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32762

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32761

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32760

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32759

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32758

Rejected reason: Not used

Apr 11, 2025
CVE-2025-32757

Rejected reason: Not used

Apr 11, 2025
CVE-2025-26335
5.8 MEDIUM

Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent Data vulnerability. A high privileged attacker with remote access …

Apr 11, 2025
CVE-2025-0128

A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate …

Apr 11, 2025
CVE-2025-0127

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root …

Apr 11, 2025
CVE-2025-0126

When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables an attacker to impersonate a legitimate authorized user and perform actions as …

Apr 11, 2025
CVE-2025-0125

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables a malicious authenticated read-write administrator to impersonate …

Apr 11, 2025
CVE-2025-0124
3.8 LOW

An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to …

Apr 11, 2025
CVE-2025-0122

A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma SD-WAN ION …

Apr 11, 2025
CVE-2025-0121

A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the …

Apr 11, 2025
CVE-2025-0120
7.0 HIGH

A vulnerability with a privilege management mechanism in the Palo Alto Networks GlobalProtect™ app on Windows devices allows a locally authenticated non-administrative Windows user to …

Apr 11, 2025
CVE-2024-51461
4.3 MEDIUM

IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupting an HTTP request that could …

Apr 11, 2025
CVE-2025-32809
6.4 MEDIUM

W. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus description, feedback.choice_fb[], or question_id.

Apr 11, 2025
CVE-2025-32808
7.7 HIGH

W. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into the backend, because only client-side access control exists.

Apr 11, 2025
CVE-2025-32807
5.3 MEDIUM

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or …

Apr 11, 2025
CVE-2025-29918
6.2 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A PCRE rule can be written that leads to an …

Apr 10, 2025
CVE-2025-29917
6.2 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The bytes setting in the decode_base64 keyword is not properly …

Apr 10, 2025
CVE-2025-29916
6.2 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have an option to specify the …

Apr 10, 2025
CVE-2025-29915
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The AF_PACKET defrag option is enabled by default and allows …

Apr 10, 2025
CVE-2025-3469

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/htmlform/fields/HTMLMultiSelectField.Php. …

Apr 10, 2025
CVE-2025-32700

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseLog.Php, includes/Pager/AbuseLogPager.Php, includes/Special/SpecialAbuseLog.Php, includes/View/AbuseFilterViewExamine.Php. This …

Apr 10, 2025
CVE-2025-32699

Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1; Parsoid: before 0.16.5, 0.19.2, 0.20.2.

Apr 10, 2025
CVE-2025-32698

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/logging/LogPager.Php. This issue affects MediaWiki: …

Apr 10, 2025
CVE-2025-32697

Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/editpage/IntroMessageBuilder.Php, includes/Permissions/PermissionManager.Php, includes/Permissions/RestrictionStore.Php. This issue affects MediaWiki: before 1.42.6, …

Apr 10, 2025
CVE-2025-32696

Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/actions/RevertAction.Php, includes/api/ApiFileRevert.Php. This issue affects MediaWiki: before 1.39.12, 1.42.6, …

Apr 10, 2025
CVE-2025-23010
7.2 HIGH

An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to manipulate …

Apr 10, 2025
CVE-2025-23009
7.2 HIGH

A local privilege escalation vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to trigger an arbitrary file deletion.

Apr 10, 2025
CVE-2025-23008
7.2 HIGH

An improper privilege management vulnerability in the SonicWall NetExtender Windows (32 and 64 bit) client allows a low privileged attacker to modify configurations.

Apr 10, 2025
CVE-2025-22232
5.3 MEDIUM

Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header when making requests to Vault. Your application may be …

Apr 10, 2025
CVE-2025-24866
2.7 LOW

Mattermost versions 9.11.x <= 9.11.8 fail to enforce proper access controls on the /api/v4/audits endpoint, allowing users with delegated granular administration roles who lack access …

Apr 10, 2025
CVE-2025-32382

Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection details in Metabase (either updating a password or changing …

Apr 10, 2025
CVE-2025-32027
6.1 MEDIUM

Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer …

Apr 10, 2025
CVE-2025-29150
4.3 MEDIUM

BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request.

Apr 10, 2025
CVE-2025-0362
6.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, …

Apr 10, 2025
CVE-2025-32743
9.0 CRITICAL

In ConnMan through 1.44, the lookup string in ns_resolv in dnsproxy.c can be NULL or an empty string when the TC (Truncated) bit is set …

Apr 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.