CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21233
8.8 HIGH

Windows Telephony Service Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21232
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21231
7.5 HIGH

IP Helper Denial of Service Vulnerability

Jan 14, 2025
CVE-2025-21230
7.5 HIGH

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

Jan 14, 2025
CVE-2025-21229
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21228
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21227
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21226
6.6 MEDIUM

Windows Digital Media Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21225
5.9 MEDIUM

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

Jan 14, 2025
CVE-2025-21224
8.1 HIGH

Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21223
8.8 HIGH

Windows Telephony Service Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21220
7.5 HIGH

Microsoft Message Queuing Information Disclosure Vulnerability

Jan 14, 2025
CVE-2025-21219
4.3 MEDIUM

MapUrlToZone Security Feature Bypass Vulnerability

Jan 14, 2025
CVE-2025-21218
7.5 HIGH

Windows Kerberos Denial of Service Vulnerability

Jan 14, 2025
CVE-2025-21217
6.5 MEDIUM

Windows NTLM Spoofing Vulnerability

Jan 14, 2025
CVE-2025-21215
4.6 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Jan 14, 2025
CVE-2025-21214
4.2 MEDIUM

Windows BitLocker Information Disclosure Vulnerability

Jan 14, 2025
CVE-2025-21213
4.6 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Jan 14, 2025
CVE-2025-21211
6.8 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Jan 14, 2025
CVE-2025-21210
4.2 MEDIUM

Windows BitLocker Information Disclosure Vulnerability

Jan 14, 2025
CVE-2025-21207
7.5 HIGH

Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability

Jan 14, 2025
CVE-2025-21202
6.1 MEDIUM

Windows Recovery Environment Agent Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21193
6.5 MEDIUM

Active Directory Federation Server Spoofing Vulnerability

Jan 14, 2025
CVE-2025-21189
4.3 MEDIUM

MapUrlToZone Security Feature Bypass Vulnerability

Jan 14, 2025
CVE-2025-21187
7.8 HIGH

Microsoft Power Automate Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21186
7.8 HIGH

Microsoft Access Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21178
8.8 HIGH

Visual Studio Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21176
8.8 HIGH

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21173
7.3 HIGH

.NET Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21172
7.5 HIGH

.NET and Visual Studio Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21171
7.5 HIGH

.NET Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-0465
7.3 HIGH

A vulnerability was found in AquilaCMS 1.412.13. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/v2/categories. …

Jan 14, 2025
CVE-2024-13172
7.8 HIGH

Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve …

Jan 14, 2025
CVE-2024-13171
7.8 HIGH

Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve …

Jan 14, 2025
CVE-2024-13170
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13169
7.8 HIGH

An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate …

Jan 14, 2025
CVE-2024-13168
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13167
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13166
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13165
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13164
7.8 HIGH

An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate …

Jan 14, 2025
CVE-2024-13163
7.8 HIGH

Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to …

Jan 14, 2025
CVE-2024-13162
7.2 HIGH

SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges …

Jan 14, 2025
CVE-2024-13161
9.8 CRITICAL KEV

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak …

Jan 14, 2025
CVE-2024-13160
9.8 CRITICAL KEV

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak …

Jan 14, 2025
CVE-2024-13159
9.8 CRITICAL KEV

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak …

Jan 14, 2025
CVE-2024-13158
7.2 HIGH

An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker …

Jan 14, 2025
CVE-2024-12747
5.6 MEDIUM

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic …

Jan 14, 2025
CVE-2024-12088
6.5 MEDIUM

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from …

Jan 14, 2025
CVE-2024-12087
6.5 MEDIUM

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can …

Jan 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.