CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-30285
8.4 HIGH

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the …

Apr 8, 2025
CVE-2025-30284
8.4 HIGH

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the …

Apr 8, 2025
CVE-2025-30282
9.1 CRITICAL

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-30281
9.1 CRITICAL

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker …

Apr 8, 2025
CVE-2025-24447
9.1 CRITICAL

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the …

Apr 8, 2025
CVE-2025-24446
9.1 CRITICAL

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution. Exploitation of this …

Apr 8, 2025
CVE-2025-22871
9.1 CRITICAL

The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http …

Apr 8, 2025
CVE-2024-12556
8.7 HIGH

Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.

Apr 8, 2025
CVE-2025-3416
3.7 LOW

A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined …

Apr 8, 2025
CVE-2025-30309
5.5 MEDIUM

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-30308
5.5 MEDIUM

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-30307
5.5 MEDIUM

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-30306
5.5 MEDIUM

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-30305
5.5 MEDIUM

XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-30304
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-30303
5.5 MEDIUM

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-30302
5.5 MEDIUM

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-30301
5.5 MEDIUM

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Apr 8, 2025
CVE-2025-30300
5.5 MEDIUM

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Apr 8, 2025
CVE-2025-30299
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-30298
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-30297
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-30296
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Apr 8, 2025
CVE-2025-30295
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-32036
4.2 MEDIUM

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. The algorithm used to generate the captcha image shows the …

Apr 8, 2025
CVE-2025-32035
2.6 LOW

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), …

Apr 8, 2025
CVE-2025-29824
7.8 HIGH KEV

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29823
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-29822
7.8 HIGH

Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.

Apr 8, 2025
CVE-2025-29821
5.5 MEDIUM

Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.

Apr 8, 2025
CVE-2025-29820
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-29819
6.2 MEDIUM

External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.

Apr 8, 2025
CVE-2025-29816
7.5 HIGH

Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.

Apr 8, 2025
CVE-2025-29812
7.8 HIGH

Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29811
7.8 HIGH

Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29810
7.5 HIGH

Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

Apr 8, 2025
CVE-2025-29809
7.1 HIGH

Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.

Apr 8, 2025
CVE-2025-29808
5.5 MEDIUM

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

Apr 8, 2025
CVE-2025-29805
7.5 HIGH

Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-29804
7.3 HIGH

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29802
7.3 HIGH

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29801
7.8 HIGH

Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29800
7.8 HIGH

Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29794
8.8 HIGH

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-29793
7.2 HIGH

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-29792
7.3 HIGH

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-29791
7.8 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27752
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27751
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27750
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Apr 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.