CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24066
7.8 HIGH

Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24064
8.1 HIGH

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-24061
7.8 HIGH

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.

Mar 11, 2025
CVE-2025-24059
7.8 HIGH

Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24057
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24056
8.8 HIGH

Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-24055
4.3 MEDIUM

Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.

Mar 11, 2025
CVE-2025-24054
6.5 MEDIUM KEV

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Mar 11, 2025
CVE-2025-24051
8.8 HIGH

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-24050
7.8 HIGH

Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24049
8.4 HIGH

Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24048
7.8 HIGH

Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24046
7.8 HIGH

Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24045
8.1 HIGH

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-24044
7.8 HIGH

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24043
7.5 HIGH

Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-24035
8.1 HIGH

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-22213

Inadequate checks in the Media Manager allowed users with "edit" privileges to change file extension to arbitrary extension, including .php and other potentially executable extensions.

Mar 11, 2025
CVE-2025-21247
4.3 MEDIUM

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

Mar 11, 2025
CVE-2025-21199
6.7 MEDIUM

Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-21180
7.8 HIGH

Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-21169
7.8 HIGH

Substance3D - Designer versions 14.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Mar 11, 2025
CVE-2025-0149
6.5 MEDIUM

Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access.

Mar 11, 2025
CVE-2024-9157
7.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a …

Mar 11, 2025
CVE-2024-56338
4.8 MEDIUM

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to …

Mar 11, 2025
CVE-2025-27617
8.8 HIGH

Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a …

Mar 11, 2025
CVE-2025-27602
4.9 MEDIUM

Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via …

Mar 11, 2025
CVE-2025-27601
4.3 MEDIUM

Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior …

Mar 11, 2025
CVE-2025-25747
5.4 MEDIUM

Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the …

Mar 11, 2025
CVE-2025-25680
7.7 HIGH

LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary …

Mar 11, 2025
CVE-2025-27403

Ratify is a verification engine as a binary executable and on Kubernetes which enables verification of artifact security metadata and admits for deployment only those …

Mar 11, 2025
CVE-2025-22454
7.8 HIGH

Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

Mar 11, 2025
CVE-2024-55597
5.5 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to execute unauthorized code …

Mar 11, 2025
CVE-2024-55592
3.8 LOW

An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, …

Mar 11, 2025
CVE-2024-55590
8.8 HIGH

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an …

Mar 11, 2025
CVE-2024-54026
4.3 MEDIUM

An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 …

Mar 11, 2025
CVE-2024-54018
7.2 HIGH

Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands …

Mar 11, 2025
CVE-2024-52961
8.8 HIGH

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through …

Mar 11, 2025
CVE-2024-52960
4.3 MEDIUM

A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at …

Mar 11, 2025
CVE-2024-51322
5.4 MEDIUM

Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/home.jsp, /jsp/gsfr_feditorHTML.jsp, /servlet/SPVisualZoom, /jsp/gsmd_container.jsp …

Mar 11, 2025
CVE-2024-51321
7.6 HIGH

In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled website after …

Mar 11, 2025
CVE-2024-51320
5.4 MEDIUM

Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servlet/gsdm_fsave_htmltmp, /servlet/gsdm_btlk_openfile components

Mar 11, 2025
CVE-2024-51319
7.3 HIGH

A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading …

Mar 11, 2025
CVE-2024-46663
6.7 MEDIUM

A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or …

Mar 11, 2025
CVE-2024-45328
7.8 HIGH

An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated CLI commands via the GUI console …

Mar 11, 2025
CVE-2024-45324
7.2 HIGH

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, …

Mar 11, 2025
CVE-2024-33501
4.2 MEDIUM

Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, …

Mar 11, 2025
CVE-2024-32123
6.7 MEDIUM

Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 …

Mar 11, 2025
CVE-2023-48790
7.5 HIGH

A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5 may allow a …

Mar 11, 2025
CVE-2023-42784
5.6 MEDIUM

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows …

Mar 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.