CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21155
5.5 MEDIUM

Substance3D - Stager versions 3.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Feb 11, 2025
CVE-2019-15002
4.3 MEDIUM

An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an …

Feb 11, 2025
CVE-2025-24472
8.1 HIGH KEV

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may …

Feb 11, 2025
CVE-2025-24470
8.6 HIGH

An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker …

Feb 11, 2025
CVE-2025-22399
7.9 HIGH

Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could potentially exploit this …

Feb 11, 2025
CVE-2025-21158
7.8 HIGH

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Feb 11, 2025
CVE-2025-21157
7.8 HIGH

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 11, 2025
CVE-2025-21126
5.5 MEDIUM

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service condition. An attacker …

Feb 11, 2025
CVE-2025-21125
5.5 MEDIUM

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Feb 11, 2025
CVE-2025-21124
5.5 MEDIUM

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 11, 2025
CVE-2025-21123
7.8 HIGH

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Feb 11, 2025
CVE-2025-21121
7.8 HIGH

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 11, 2025
CVE-2025-1126
9.3 CRITICAL

A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.

Feb 11, 2025
CVE-2024-52968
6.7 MEDIUM

An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.

Feb 11, 2025
CVE-2024-52966
2.3 LOW

An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.

Feb 11, 2025
CVE-2024-50569
6.6 MEDIUM

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allows attacker to execute unauthorized …

Feb 11, 2025
CVE-2024-50567
7.2 HIGH

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacker to execute unauthorized …

Feb 11, 2025
CVE-2024-40591
8.8 HIGH

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose …

Feb 11, 2025
CVE-2024-40586
6.7 MEDIUM

An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to …

Feb 11, 2025
CVE-2024-40584
7.2 HIGH

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through …

Feb 11, 2025
CVE-2024-36508
6.0 MEDIUM

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and …

Feb 11, 2025
CVE-2024-35279
8.1 HIGH

A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute …

Feb 11, 2025
CVE-2024-33504
4.1 MEDIUM

A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all …

Feb 11, 2025
CVE-2024-27781
7.1 HIGH

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through …

Feb 11, 2025
CVE-2024-27780
2.2 LOW

Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident …

Feb 11, 2025
CVE-2024-12756
7.3 HIGH

An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the user.

Feb 11, 2025
CVE-2024-12755
7.9 HIGH

A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential disclose of sensitive information.

Feb 11, 2025
CVE-2023-40721
6.7 MEDIUM

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.

Feb 11, 2025
CVE-2025-24976

Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be …

Feb 11, 2025
CVE-2025-24973
9.3 CRITICAL

Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1, due to an improper implementation of the …

Feb 11, 2025
CVE-2025-24900
8.6 HIGH

Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Due to a lack of CSRF countermeasures and improper settings of …

Feb 11, 2025
CVE-2025-24897
8.2 HIGH

Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF protection …

Feb 11, 2025
CVE-2025-24896
8.1 HIGH

Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named `token` is stored …

Feb 11, 2025
CVE-2025-24807
7.1 HIGH

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.10, 2.10.7, …

Feb 11, 2025
CVE-2025-22467
9.9 CRITICAL

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.

Feb 11, 2025
CVE-2024-47908
9.1 CRITICAL

OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote …

Feb 11, 2025
CVE-2024-13843
6.0 MEDIUM

Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin …

Feb 11, 2025
CVE-2024-13842
6.0 MEDIUM

A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges …

Feb 11, 2025
CVE-2024-13830
6.1 MEDIUM

Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. …

Feb 11, 2025
CVE-2024-13813
7.1 HIGH

Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.

Feb 11, 2025
CVE-2024-12797
6.3 MEDIUM

Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes …

Feb 11, 2025
CVE-2024-12058
6.8 MEDIUM

External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker …

Feb 11, 2025
CVE-2024-11771
5.3 MEDIUM

Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.

Feb 11, 2025
CVE-2024-10644
9.1 CRITICAL

Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to …

Feb 11, 2025
CVE-2024-33659
8.8 HIGH

AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker. Successful exploitation of these vulnerabilities …

Feb 11, 2025
CVE-2025-26493
4.6 MEDIUM

In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab

Feb 11, 2025
CVE-2025-26492
7.7 HIGH

In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources

Feb 11, 2025
CVE-2025-1231
5.4 MEDIUM

Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password after check-in due …

Feb 11, 2025
CVE-2024-12366
9.8 CRITICAL

PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) …

Feb 11, 2025
CVE-2025-0588
4.9 MEDIUM

In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting …

Feb 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.