CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21134
7.8 HIGH

Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Jan 14, 2025
CVE-2025-21133
7.8 HIGH

Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Jan 14, 2025
CVE-2025-21132
7.8 HIGH

Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jan 14, 2025
CVE-2025-21131
7.8 HIGH

Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jan 14, 2025
CVE-2025-21130
7.8 HIGH

Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jan 14, 2025
CVE-2025-21129
7.8 HIGH

Substance3D - Stager versions 3.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jan 14, 2025
CVE-2025-21128
7.8 HIGH

Substance3D - Stager versions 3.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jan 14, 2025
CVE-2025-21127
7.8 HIGH

Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker …

Jan 14, 2025
CVE-2025-21122
7.8 HIGH

Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Jan 14, 2025
CVE-2025-0474
7.7 HIGH

Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue …

Jan 14, 2025
CVE-2024-56374
5.8 MEDIUM

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when …

Jan 14, 2025
CVE-2024-52006
7.5 HIGH

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. …

Jan 14, 2025
CVE-2024-50349
4.7 MEDIUM

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. …

Jan 14, 2025
CVE-2024-50338
7.4 HIGH

Git Credential Manager (GCM) is a secure Git credential helper built on .NET that runs on Windows, macOS, and Linux. The Git credential protocol is …

Jan 14, 2025
CVE-2024-49375
9.0 CRITICAL

Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciously crafted …

Jan 14, 2025
CVE-2024-48857
7.5 HIGH

NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service …

Jan 14, 2025
CVE-2024-48856
9.8 CRITICAL

Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition …

Jan 14, 2025
CVE-2024-48855
5.3 MEDIUM

Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure …

Jan 14, 2025
CVE-2024-48854
5.3 MEDIUM

Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure …

Jan 14, 2025
CVE-2025-23366
6.5 MEDIUM

A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed …

Jan 14, 2025
CVE-2025-23052
7.2 HIGH

Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute …

Jan 14, 2025
CVE-2025-23051
7.2 HIGH

An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user …

Jan 14, 2025
CVE-2025-23025
9.0 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension was **experimental**, …

Jan 14, 2025
CVE-2025-21607
7.5 HIGH

Vyper is a Pythonic Smart Contract Language for the EVM. When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), the success flag …

Jan 14, 2025
CVE-2025-21417
8.8 HIGH

Windows Telephony Service Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21413
8.8 HIGH

Windows Telephony Service Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21411
8.8 HIGH

Windows Telephony Service Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21409
8.8 HIGH

Windows Telephony Service Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21405
7.3 HIGH

Visual Studio Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21403
6.4 MEDIUM

On-Premises Data Gateway Information Disclosure Vulnerability

Jan 14, 2025
CVE-2025-21402
7.8 HIGH

Microsoft Office OneNote Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21395
7.8 HIGH

Microsoft Access Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21393
6.3 MEDIUM

Microsoft SharePoint Server Spoofing Vulnerability

Jan 14, 2025
CVE-2025-21389
7.5 HIGH

Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.

Jan 14, 2025
CVE-2025-21382
7.8 HIGH

Windows Graphics Component Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21378
7.8 HIGH

Windows CSC Service Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21374
5.5 MEDIUM

Windows CSC Service Information Disclosure Vulnerability

Jan 14, 2025
CVE-2025-21372
7.8 HIGH

Microsoft Brokering File System Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21370
7.8 HIGH

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21366
7.8 HIGH

Microsoft Access Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21365
7.8 HIGH

Microsoft Office Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21364
7.8 HIGH

Microsoft Excel Security Feature Bypass Vulnerability

Jan 14, 2025
CVE-2025-21363
7.8 HIGH

Microsoft Word Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21362
8.4 HIGH

Microsoft Excel Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21361
7.8 HIGH

Microsoft Outlook Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21360
7.8 HIGH

Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21357
6.7 MEDIUM

Microsoft Outlook Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21356
7.8 HIGH

Microsoft Office Visio Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21354
8.4 HIGH

Microsoft Excel Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21348
7.2 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Jan 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.