CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-48001
6.8 MEDIUM

Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Jul 8, 2025
CVE-2025-47999
6.8 MEDIUM

Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

Jul 8, 2025
CVE-2025-47980
6.2 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

Jul 8, 2025
CVE-2025-47978
6.5 MEDIUM

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

Jul 8, 2025
CVE-2025-47109
5.5 MEDIUM

After Effects versions 25.2, 24.6.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit …

Jul 8, 2025
CVE-2025-43587
5.5 MEDIUM

After Effects versions 25.2, 24.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jul 8, 2025
CVE-2025-43580
5.5 MEDIUM

Audition versions 25.2, 24.6.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerability that could result in application denial-of-service. …

Jul 8, 2025
CVE-2025-26636
5.5 MEDIUM

Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally.

Jul 8, 2025
CVE-2025-21195
6.0 MEDIUM

Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.

Jul 8, 2025
CVE-2025-21168
5.5 MEDIUM

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jul 8, 2025
CVE-2025-21167
5.5 MEDIUM

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jul 8, 2025
CVE-2024-36357
5.6 MEDIUM

A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of …

Jul 8, 2025
CVE-2024-36350
5.6 MEDIUM

A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged …

Jul 8, 2025
CVE-2025-5464
6.5 MEDIUM

Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain that information.

Jul 8, 2025
CVE-2025-0293
6.6 MEDIUM

CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to …

Jul 8, 2025
CVE-2025-0292
5.5 MEDIUM

SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to access …

Jul 8, 2025
CVE-2025-7182
4.3 MEDIUM

A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Jul 8, 2025
CVE-2025-5463
5.5 MEDIUM

Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local …

Jul 8, 2025
CVE-2025-5451
4.9 MEDIUM

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin …

Jul 8, 2025
CVE-2025-5450
6.3 MEDIUM

Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote …

Jul 8, 2025
CVE-2025-53480
5.4 MEDIUM

The CheckUser extension’s Special:Investigate page has a vulnerability in the Account information tab, where specific internationalized messages are rendered without proper escaping. Attackers can exploit …

Jul 8, 2025
CVE-2025-3630
6.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to stored …

Jul 8, 2025
CVE-2025-2827
4.3 MEDIUM

IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used …

Jul 8, 2025
CVE-2025-2793
5.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site …

Jul 8, 2025
CVE-2025-29267
6.5 MEDIUM

SQL Injection vulnerability in Abis, Inc Adjutant Core Accounting ERP build v.PreBeta250F allows a remote attacker to obtain a sensitive information via the cid parameter …

Jul 8, 2025
CVE-2024-55599
5.3 MEDIUM

An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy …

Jul 8, 2025
CVE-2025-7181
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Staff Audit System 1.0. Affected is an unknown function of the file /test.php. The …

Jul 8, 2025
CVE-2025-21433
6.2 MEDIUM

Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.

Jul 8, 2025
CVE-2025-21426
6.6 MEDIUM

Memory corruption while processing camera TPG write request.

Jul 8, 2025
CVE-2024-53009
5.3 MEDIUM

Memory corruption while operating the mailbox in Automotive.

Jul 8, 2025
CVE-2025-7177
4.7 MEDIUM

A vulnerability was found in PHPGurukul Car Washing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 8, 2025
CVE-2025-40721
5.4 MEDIUM

Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in …

Jul 8, 2025
CVE-2025-40720
6.1 MEDIUM

Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in …

Jul 8, 2025
CVE-2025-40719
6.1 MEDIUM

Reflected Cross-site Scripting (XSS) vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to execute JavaScript code in …

Jul 8, 2025
CVE-2025-7175
6.3 MEDIUM

A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/users_photo.php. The …

Jul 8, 2025
CVE-2025-41223
4.8 MEDIUM

A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All versions), RUGGEDCOM i803 (All versions), RUGGEDCOM M2100 (All …

Jul 8, 2025
CVE-2025-41222
5.3 MEDIUM

A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All versions), RUGGEDCOM i803 (All versions), RUGGEDCOM M2100 (All …

Jul 8, 2025
CVE-2025-40742
5.3 MEDIUM

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All …

Jul 8, 2025
CVE-2025-40593
6.5 MEDIUM

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0). The affected application allows to control the device by storing arbitrary files …

Jul 8, 2025
CVE-2025-27127
4.3 MEDIUM

A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All …

Jul 8, 2025
CVE-2025-23364
6.2 MEDIUM

A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signing certificates. This could allow an attacker …

Jul 8, 2025
CVE-2025-21009
5.5 MEDIUM

Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

Jul 8, 2025
CVE-2025-21008
5.5 MEDIUM

Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

Jul 8, 2025
CVE-2025-21007
5.5 MEDIUM

Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

Jul 8, 2025
CVE-2025-21005
5.5 MEDIUM

Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information.

Jul 8, 2025
CVE-2025-21004
6.2 MEDIUM

Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off …

Jul 8, 2025
CVE-2025-21003
4.0 MEDIUM

Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.

Jul 8, 2025
CVE-2025-21002
6.2 MEDIUM

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.

Jul 8, 2025
CVE-2025-21001
6.2 MEDIUM

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.

Jul 8, 2025
CVE-2025-21000
6.2 MEDIUM

Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.

Jul 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.