CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-55679
5.1 MEDIUM

Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-55676
5.5 MEDIUM

Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-55338
6.1 MEDIUM

Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Oct 14, 2025
CVE-2025-55337
6.1 MEDIUM

Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Oct 14, 2025
CVE-2025-55336
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-55334
6.2 MEDIUM

Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally.

Oct 14, 2025
CVE-2025-55333
6.1 MEDIUM

Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Oct 14, 2025
CVE-2025-55332
6.1 MEDIUM

Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Oct 14, 2025
CVE-2025-55330
6.1 MEDIUM

Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Oct 14, 2025
CVE-2025-55325
5.5 MEDIUM

Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-55320
6.8 MEDIUM

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an …

Oct 14, 2025
CVE-2025-55248
4.8 MEDIUM

Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

Oct 14, 2025
CVE-2025-54603
6.5 MEDIUM

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.

Oct 14, 2025
CVE-2025-48813
6.3 MEDIUM

Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.

Oct 14, 2025
CVE-2025-47979
5.5 MEDIUM

Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-37148
6.5 MEDIUM

A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of …

Oct 14, 2025
CVE-2025-37145
4.9 MEDIUM

Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated …

Oct 14, 2025
CVE-2025-37144
4.9 MEDIUM

Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated …

Oct 14, 2025
CVE-2025-37143
4.9 MEDIUM

An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an …

Oct 14, 2025
CVE-2025-37142
4.9 MEDIUM

Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious …

Oct 14, 2025
CVE-2025-37141
4.9 MEDIUM

Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious …

Oct 14, 2025
CVE-2025-37140
4.9 MEDIUM

Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious …

Oct 14, 2025
CVE-2025-37139
6.0 MEDIUM

A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploitation may render the system unbootable, …

Oct 14, 2025
CVE-2025-37138
6.2 MEDIUM

An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability …

Oct 14, 2025
CVE-2025-37137
6.5 MEDIUM

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated …

Oct 14, 2025
CVE-2025-37136
6.5 MEDIUM

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated …

Oct 14, 2025
CVE-2025-37135
6.5 MEDIUM

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated …

Oct 14, 2025
CVE-2025-8429
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (ACL Action access configuration modules) allows Stored XSS …

Oct 14, 2025
CVE-2025-59921
6.5 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version 7.1.4 and below, 7.0 …

Oct 14, 2025
CVE-2025-58324
6.4 MEDIUM

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, …

Oct 14, 2025
CVE-2025-57716
6.7 MEDIUM

An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged …

Oct 14, 2025
CVE-2025-54973
5.3 MEDIUM

A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through …

Oct 14, 2025
CVE-2025-54893
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hosts templates configuration modules) allows Stored XSS by …

Oct 14, 2025
CVE-2025-54822
4.3 MEDIUM

An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.8, FortiOS 7.0.0 through 7.0.11, FortiProxy 7.4.0 through 7.4.8, FortiProxy …

Oct 14, 2025
CVE-2025-53845
6.5 MEDIUM

An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the …

Oct 14, 2025
CVE-2025-37149
6.0 MEDIUM

A potential out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware.

Oct 14, 2025
CVE-2025-31366
4.7 MEDIUM

An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all …

Oct 14, 2025
CVE-2025-31365
5.8 MEDIUM

An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to …

Oct 14, 2025
CVE-2025-25255
5.3 MEDIUM

An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.11, FortiProxy …

Oct 14, 2025
CVE-2025-25252
4.8 MEDIUM

An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions …

Oct 14, 2025
CVE-2025-22258
6.5 MEDIUM

A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through …

Oct 14, 2025
CVE-2024-47569
4.3 MEDIUM

A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 …

Oct 14, 2025
CVE-2024-26008
5.3 MEDIUM

An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and …

Oct 14, 2025
CVE-2023-46718
6.7 MEDIUM

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2.9 …

Oct 14, 2025
CVE-2025-8428
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (HTTP Loader widget modules) allows Stored XSS.This issue …

Oct 14, 2025
CVE-2025-62157
6.5 MEDIUM

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Argo Workflows versions prior to 3.6.12 and versions 3.7.0 through …

Oct 14, 2025
CVE-2025-59428
5.4 MEDIUM

EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows arbitrary user creation, including administrative accounts, through a combination …

Oct 14, 2025
CVE-2025-56747
6.5 MEDIUM

Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authenticated users can access instructor-only functions …

Oct 14, 2025
CVE-2025-54892
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (SNMP traps group configuration modules) allows Stored XSS …

Oct 14, 2025
CVE-2025-54891
6.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (ACL Resource access configuration modules) allows Stored XSS …

Oct 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.