CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-31360
7.3 HIGH

Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in …

Feb 11, 2025
CVE-2025-25524
5.1 MEDIUM

Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. …

Feb 11, 2025
CVE-2025-25523
5.9 MEDIUM

Buffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related to the mobile access point …

Feb 11, 2025
CVE-2025-25522
7.3 HIGH

Buffer overflow vulnerability in Linksys WAP610N v1.0.05.002 due to the lack of length verification, which is related to the time setting operation. The attacker can …

Feb 11, 2025
CVE-2025-25202
6.5 MEDIUM

Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present since AshAuthentication v4.1.0 and who have …

Feb 11, 2025
CVE-2022-35202
5.1 MEDIUM

A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private keys used …

Feb 11, 2025
CVE-2025-26495
7.5 HIGH

Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Tableau Server: before …

Feb 11, 2025
CVE-2025-26494
7.7 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server allows Authentication Bypass.This issue affects Tableau Server: from 2023.3 through 2023.3.5.

Feb 11, 2025
CVE-2025-24438
8.7 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Feb 11, 2025
CVE-2025-24437
5.4 MEDIUM

Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24436
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24435
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A …

Feb 11, 2025
CVE-2025-24434
9.1 CRITICAL

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker …

Feb 11, 2025
CVE-2025-24432
3.7 LOW

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a …

Feb 11, 2025
CVE-2025-24430
3.7 LOW

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a …

Feb 11, 2025
CVE-2025-24429
3.5 LOW

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24428
5.4 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Feb 11, 2025
CVE-2025-24427
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24426
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24425
5.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Business Logic Error vulnerability that could result in a security feature …

Feb 11, 2025
CVE-2025-24424
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24423
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A …

Feb 11, 2025
CVE-2025-24422
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24421
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24420
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24419
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24418
8.1 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged …

Feb 11, 2025
CVE-2025-24417
8.7 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Feb 11, 2025
CVE-2025-24416
8.7 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Feb 11, 2025
CVE-2025-24415
8.7 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Feb 11, 2025
CVE-2025-24414
8.7 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Feb 11, 2025
CVE-2025-24413
8.7 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Feb 11, 2025
CVE-2025-24412
8.7 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Feb 11, 2025
CVE-2025-24411
8.1 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24410
8.7 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Feb 11, 2025
CVE-2025-24409
8.2 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. …

Feb 11, 2025
CVE-2025-24408
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged …

Feb 11, 2025
CVE-2025-24407
7.1 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24406
7.5 HIGH

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') …

Feb 11, 2025
CVE-2025-24042
7.3 HIGH

Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability

Feb 11, 2025
CVE-2025-24039
7.3 HIGH

Visual Studio Code Elevation of Privilege Vulnerability

Feb 11, 2025
CVE-2025-24036
7.0 HIGH

Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

Feb 11, 2025
CVE-2025-21420
7.8 HIGH

Windows Disk Cleanup Tool Elevation of Privilege Vulnerability

Feb 11, 2025
CVE-2025-21419
7.1 HIGH

Windows Setup Files Cleanup Elevation of Privilege Vulnerability

Feb 11, 2025
CVE-2025-21418
7.8 HIGH KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Feb 11, 2025
CVE-2025-21414
7.0 HIGH

Windows Core Messaging Elevation of Privileges Vulnerability

Feb 11, 2025
CVE-2025-21410
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Feb 11, 2025
CVE-2025-21407
8.8 HIGH

Windows Telephony Service Remote Code Execution Vulnerability

Feb 11, 2025
CVE-2025-21406
8.8 HIGH

Windows Telephony Service Remote Code Execution Vulnerability

Feb 11, 2025
CVE-2025-21400
8.0 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Feb 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.