CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-31647
6.7 MEDIUM

Uncontrolled search path for some Intel(R) Graphics Software before version 25.22.1502.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary …

Nov 11, 2025
CVE-2025-31645
6.7 MEDIUM

Uncontrolled search path for some System Event Log Viewer Utility software for all versions within Ring 3: User Applications may allow an escalation of privilege. …

Nov 11, 2025
CVE-2025-31146
6.1 MEDIUM

Time-of-check time-of-use race condition for some Intel Ethernet Adapter Complete Driver Pack software before version 1.5.1.0 within Ring 3: User Applications may allow a denial …

Nov 11, 2025
CVE-2025-30518
6.7 MEDIUM

Incorrect default permissions for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with …

Nov 11, 2025
CVE-2025-30506
6.7 MEDIUM

Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged …

Nov 11, 2025
CVE-2025-30182
6.7 MEDIUM

Uncontrolled search path for some Intel(R) Distribution for Python software installers before version 2025.2.0 within Ring 3: User Applications may allow an escalation of privilege. …

Nov 11, 2025
CVE-2025-27725
4.4 MEDIUM

Time-of-check time-of-use race condition for some ACAT before version 3.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with …

Nov 11, 2025
CVE-2025-27712
5.7 MEDIUM

Improper neutralization for some Intel(R) Neural Compressor software before version v3.4 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary …

Nov 11, 2025
CVE-2025-27711
6.7 MEDIUM

Incorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation …

Nov 11, 2025
CVE-2025-27710
6.5 MEDIUM

Untrusted pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an information disclosure. System software adversary …

Nov 11, 2025
CVE-2025-27249
5.5 MEDIUM

Uncontrolled resource consumption for some Gaudi software before version 1.21.0 within Ring 3: User Applications may allow a denial of service. System software adversary with …

Nov 11, 2025
CVE-2025-27246
6.7 MEDIUM

Incorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software …

Nov 11, 2025
CVE-2025-26694
5.5 MEDIUM

Null pointer dereference for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software …

Nov 11, 2025
CVE-2025-26405
5.9 MEDIUM

Improper control of dynamically-managed code resources for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary …

Nov 11, 2025
CVE-2025-26402
6.5 MEDIUM

Protection mechanism failure for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated …

Nov 11, 2025
CVE-2025-25059
6.7 MEDIUM

Uncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation …

Nov 11, 2025
CVE-2025-24918
6.7 MEDIUM

Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software and Intel(R) Server Firmware Update Utility software before version 16.0.12. …

Nov 11, 2025
CVE-2025-24863
6.5 MEDIUM

Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with …

Nov 11, 2025
CVE-2025-24848
6.3 MEDIUM

Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary …

Nov 11, 2025
CVE-2025-24847
4.5 MEDIUM

Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with …

Nov 11, 2025
CVE-2025-24842
6.7 MEDIUM

Uncontrolled search path for the Intel(R) System Support Utility before version 4.1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software …

Nov 11, 2025
CVE-2025-24834
6.5 MEDIUM

Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with …

Nov 11, 2025
CVE-2025-24519
6.5 MEDIUM

Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary …

Nov 11, 2025
CVE-2025-24516
4.5 MEDIUM

Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with …

Nov 11, 2025
CVE-2025-24512
5.6 MEDIUM

Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. …

Nov 11, 2025
CVE-2025-24491
6.7 MEDIUM

Uncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.1465 within Ring 3: User Applications may allow an escalation of …

Nov 11, 2025
CVE-2025-24327
6.7 MEDIUM

Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before version 20.0.1021 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged …

Nov 11, 2025
CVE-2025-22391
6.7 MEDIUM

Improper access control for some SigTest before version 6.1.10 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an …

Nov 11, 2025
CVE-2025-20614
6.7 MEDIUM

External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of …

Nov 11, 2025
CVE-2025-20065
6.7 MEDIUM

Uncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Device Drivers may allow an escalation of privilege. …

Nov 11, 2025
CVE-2025-20056
4.4 MEDIUM

Improper input validation for some Intel VTune Profiler before version 2025.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary …

Nov 11, 2025
CVE-2025-20050
6.7 MEDIUM

Uncontrolled search path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary …

Nov 11, 2025
CVE-2025-12940
5.5 MEDIUM

Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed …

Nov 11, 2025
CVE-2025-13013
6.1 MEDIUM

Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and …

Nov 11, 2025
CVE-2025-10905
4.4 MEDIUM

Collision in MiniFilter driver in Avast Software Avast Free Antivirus before 25.9 on Windows allows a local attacker with administrative privileges to disable real-time protection …

Nov 11, 2025
CVE-2025-9227
6.5 MEDIUM

Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.

Nov 11, 2025
CVE-2025-41106
5.4 MEDIUM

HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user …

Nov 11, 2025
CVE-2025-41105
5.4 MEDIUM

HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user …

Nov 11, 2025
CVE-2025-41104
5.4 MEDIUM

HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user …

Nov 11, 2025
CVE-2025-41103
5.4 MEDIUM

HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user …

Nov 11, 2025
CVE-2025-41102
5.4 MEDIUM

HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user …

Nov 11, 2025
CVE-2025-41101
5.4 MEDIUM

HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user …

Nov 11, 2025
CVE-2025-11960
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aryom Software High Technology Systems Inc. KVKNET allows Reflected XSS.This issue …

Nov 11, 2025
CVE-2025-12953
4.3 MEDIUM

The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Nov 11, 2025
CVE-2025-12788
5.3 MEDIUM

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment verification to unauthenticated payment bypass in all versions …

Nov 11, 2025
CVE-2025-12787
5.3 MEDIUM

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking cancellation in all versions up to, and including, …

Nov 11, 2025
CVE-2025-9524
4.3 MEDIUM

The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usability. This vulnerability can only be exploited …

Nov 11, 2025
CVE-2025-9055
6.4 MEDIUM

The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain Linux Root privileges. This flaw can only be …

Nov 11, 2025
CVE-2025-5317
5.5 MEDIUM

An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 allows local users with administrative privileges to bypass …

Nov 11, 2025
CVE-2025-8108
6.7 MEDIUM

An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if …

Nov 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.