CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24073
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-24062
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-24060
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-24058
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-21222
8.8 HIGH

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-21221
8.8 HIGH

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-21205
8.8 HIGH

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-21204
7.8 HIGH

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-21203
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-21197
6.5 MEDIUM

Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to …

Apr 8, 2025
CVE-2025-21191
7.0 HIGH

Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-21174
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-32279
4.3 MEDIUM

Missing Authorization vulnerability in Shahjada Live Forms liveforms.This issue affects Live Forms: from n/a through <= 4.8.5.

Apr 8, 2025
CVE-2025-32211
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet Broadstreet Ads broadstreet allows Stored XSS.This issue affects Broadstreet Ads: from n/a …

Apr 8, 2025
CVE-2025-32164
6.5 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadList m1downloadlist allows Retrieve Embedded Sensitive Data.This issue affects m1.DownloadList: from n/a …

Apr 8, 2025
CVE-2025-32117
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Reflected XSS.This issue affects Widgetize Pages Light: …

Apr 8, 2025
CVE-2025-30671
6.5 MEDIUM

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Apr 8, 2025
CVE-2025-30670
6.5 MEDIUM

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Apr 8, 2025
CVE-2025-27443
2.8 LOW

Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access.

Apr 8, 2025
CVE-2025-27442
4.6 MEDIUM

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

Apr 8, 2025
CVE-2025-27441
4.6 MEDIUM

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

Apr 8, 2025
CVE-2025-27085
4.9 MEDIUM

Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote …

Apr 8, 2025
CVE-2025-27084
5.4 MEDIUM

A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting …

Apr 8, 2025
CVE-2025-27083
7.2 HIGH

Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker …

Apr 8, 2025
CVE-2025-27082
7.2 HIGH

Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow …

Apr 8, 2025
CVE-2025-25227
7.5 HIGH

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Apr 8, 2025
CVE-2025-25226
9.8 CRITICAL

Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a …

Apr 8, 2025
CVE-2024-52981
4.9 MEDIUM

An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.

Apr 8, 2025
CVE-2024-52980
6.5 MEDIUM

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. …

Apr 8, 2025
CVE-2024-52974
6.5 MEDIUM

An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful attack …

Apr 8, 2025
CVE-2024-48887
9.8 CRITICAL

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

Apr 8, 2025
CVE-2025-3289
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation …

Apr 8, 2025
CVE-2025-3288
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory …

Apr 8, 2025
CVE-2025-3287
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation …

Apr 8, 2025
CVE-2025-3286
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory …

Apr 8, 2025
CVE-2025-3285
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory …

Apr 8, 2025
CVE-2025-32028
9.9 CRITICAL

HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a …

Apr 8, 2025
CVE-2025-32026
3.8 LOW

Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to version 1.11.96, can be …

Apr 8, 2025
CVE-2025-32025

bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The buffer created for …

Apr 8, 2025
CVE-2025-32024

bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The EXIF data format …

Apr 8, 2025
CVE-2025-32018
8.0 HIGH

Cursor is a code editor built for programming with AI. In versions 0.45.0 through 0.48.6, the Cursor app introduced a regression affecting the set of …

Apr 8, 2025
CVE-2025-32017
8.8 HIGH

Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that …

Apr 8, 2025
CVE-2025-2829
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory …

Apr 8, 2025
CVE-2025-2293
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory …

Apr 8, 2025
CVE-2025-2288
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory …

Apr 8, 2025
CVE-2025-2287
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied …

Apr 8, 2025
CVE-2025-2286
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied …

Apr 8, 2025
CVE-2025-2285
7.8 HIGH

A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied …

Apr 8, 2025
CVE-2025-27079
6.0 MEDIUM

A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to …

Apr 8, 2025
CVE-2025-27078
6.5 MEDIUM

A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating …

Apr 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.