CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-10406
5.5 MEDIUM

The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any …

Oct 15, 2025
CVE-2025-55079
5.5 MEDIUM

In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't …

Oct 15, 2025
CVE-2025-54278
5.5 MEDIUM

Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this …

Oct 15, 2025
CVE-2025-54270
5.5 MEDIUM

Animate versions 23.0.13, 24.0.10 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to memory exposure. An attacker could leverage this …

Oct 15, 2025
CVE-2025-54269
5.5 MEDIUM

Animate versions 23.0.13, 24.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability …

Oct 15, 2025
CVE-2025-61797
5.4 MEDIUM

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Oct 14, 2025
CVE-2025-61796
5.4 MEDIUM

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Oct 14, 2025
CVE-2025-54272
5.4 MEDIUM

Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker …

Oct 14, 2025
CVE-2025-54196
4.3 MEDIUM

Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to …

Oct 14, 2025
CVE-2025-54267
6.5 MEDIUM

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability …

Oct 14, 2025
CVE-2025-54266
4.8 MEDIUM

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by …

Oct 14, 2025
CVE-2025-54265
5.9 MEDIUM

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to …

Oct 14, 2025
CVE-2025-62374
6.4 MEDIUM

Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to …

Oct 14, 2025
CVE-2025-60540
6.5 MEDIUM

karakeep v0.26.0 to v0.7.0 was discovered to contain a Server-Side Request Forgery (SSRF).

Oct 14, 2025
CVE-2025-60374
6.1 MEDIUM

Stored Cross-Site Scripting (XSS) in Perfex CRM chatbot before 3.3.1 allows attackers to inject arbitrary HTML/JavaScript. The payload is executed in the browsers of users …

Oct 14, 2025
CVE-2025-59429
5.4 MEDIUM

FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17, …

Oct 14, 2025
CVE-2025-33177
5.5 MEDIUM

NVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could allow a local attacker to cause memory …

Oct 14, 2025
CVE-2025-54275
5.5 MEDIUM

Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this …

Oct 14, 2025
CVE-2025-60537
6.5 MEDIUM

Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows attackers to execute arbitrary code via supplying crafted data.

Oct 14, 2025
CVE-2025-57563
6.5 MEDIUM

A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows unauthenticated attackers to read arbitrary files.

Oct 14, 2025
CVE-2025-8430
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Commands Connectors configuration modules) allows Stored XSS by …

Oct 14, 2025
CVE-2025-59288
5.3 MEDIUM

Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.

Oct 14, 2025
CVE-2025-59260
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59259
6.5 MEDIUM

Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

Oct 14, 2025
CVE-2025-59258
6.2 MEDIUM

Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59257
6.5 MEDIUM

Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

Oct 14, 2025
CVE-2025-59253
5.5 MEDIUM

Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

Oct 14, 2025
CVE-2025-59244
6.5 MEDIUM

External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.

Oct 14, 2025
CVE-2025-59229
5.5 MEDIUM

Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.

Oct 14, 2025
CVE-2025-59214
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

Oct 14, 2025
CVE-2025-59211
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59209
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59204
5.5 MEDIUM

Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59203
5.5 MEDIUM

Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59198
5.0 MEDIUM

Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

Oct 14, 2025
CVE-2025-59197
5.5 MEDIUM

Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59190
5.5 MEDIUM

Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.

Oct 14, 2025
CVE-2025-59188
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59186
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59185
6.5 MEDIUM

External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.

Oct 14, 2025
CVE-2025-59184
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-58739
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

Oct 14, 2025
CVE-2025-58729
6.5 MEDIUM

Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

Oct 14, 2025
CVE-2025-58719
4.7 MEDIUM

Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-58717
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Oct 14, 2025
CVE-2025-55700
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Oct 14, 2025
CVE-2025-55699
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-55695
5.5 MEDIUM

Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-55683
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-55682
6.1 MEDIUM

Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Oct 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.