CVE Database

38680+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-21178
8.8 HIGH

Visual Studio Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21176
8.8 HIGH

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21173
7.3 HIGH

.NET Elevation of Privilege Vulnerability

Jan 14, 2025
CVE-2025-21172
7.5 HIGH

.NET and Visual Studio Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-21171
7.5 HIGH

.NET Remote Code Execution Vulnerability

Jan 14, 2025
CVE-2025-0465
7.3 HIGH

A vulnerability was found in AquilaCMS 1.412.13. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/v2/categories. …

Jan 14, 2025
CVE-2024-13172
7.8 HIGH

Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve …

Jan 14, 2025
CVE-2024-13171
7.8 HIGH

Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve …

Jan 14, 2025
CVE-2024-13170
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13169
7.8 HIGH

An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate …

Jan 14, 2025
CVE-2024-13168
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13167
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13166
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13165
7.5 HIGH

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause …

Jan 14, 2025
CVE-2024-13164
7.8 HIGH

An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate …

Jan 14, 2025
CVE-2024-13163
7.8 HIGH

Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to …

Jan 14, 2025
CVE-2024-13162
7.2 HIGH

SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges …

Jan 14, 2025
CVE-2024-13158
7.2 HIGH

An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker …

Jan 14, 2025
CVE-2024-12085
7.5 HIGH

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length …

Jan 14, 2025
CVE-2024-53561
8.7 HIGH

A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute arbitrary code via a crafted request.

Jan 14, 2025
CVE-2024-13181
7.3 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.

Jan 14, 2025
CVE-2024-13180
7.5 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.

Jan 14, 2025
CVE-2024-13179
7.3 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.

Jan 14, 2025
CVE-2024-10630
7.8 HIGH

A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.

Jan 14, 2025
CVE-2025-22984
7.5 HIGH

An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.

Jan 14, 2025
CVE-2025-22983
7.5 HIGH

An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.

Jan 14, 2025
CVE-2025-0460
7.3 HIGH

A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the …

Jan 14, 2025
CVE-2024-42444
7.5 HIGH

APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful exploitation of this vulnerability may lead …

Jan 14, 2025
CVE-2024-7344
8.2 HIGH

Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.

Jan 14, 2025
CVE-2024-50566
7.2 HIGH

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 …

Jan 14, 2025
CVE-2024-48884
7.5 HIGH

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud …

Jan 14, 2025
CVE-2024-47571
8.1 HIGH

An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via …

Jan 14, 2025
CVE-2024-46670
7.5 HIGH

An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE …

Jan 14, 2025
CVE-2024-46668
7.5 HIGH

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and …

Jan 14, 2025
CVE-2024-46667
7.5 HIGH

A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 …

Jan 14, 2025
CVE-2024-36512
7.2 HIGH

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 …

Jan 14, 2025
CVE-2024-35277
8.6 HIGH

A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 …

Jan 14, 2025
CVE-2024-35273
7.2 HIGH

A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http …

Jan 14, 2025
CVE-2024-27778
8.8 HIGH

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox …

Jan 14, 2025
CVE-2024-23106
8.1 HIGH

An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute …

Jan 14, 2025
CVE-2024-11864
7.5 HIGH

Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash …

Jan 14, 2025
CVE-2024-11497
8.8 HIGH

An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.

Jan 14, 2025
CVE-2023-37937
7.8 HIGH

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 …

Jan 14, 2025
CVE-2023-37931
8.8 HIGH

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 …

Jan 14, 2025
CVE-2024-56841
7.4 HIGH

A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerable to LDAP injection. This could allow …

Jan 14, 2025
CVE-2024-47100
7.1 HIGH

A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7211-1HE40-0XB0), SIMATIC …

Jan 14, 2025
CVE-2025-20620
7.5 HIGH

SQL Injection vulnerability exists in STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can access the affected product may obtain the administrative password of …

Jan 14, 2025
CVE-2025-20016
7.2 HIGH

OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporation. A user with an administrative privilege who logged in to …

Jan 14, 2025
CVE-2025-0394
8.8 HIGH

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file uploads due to …

Jan 14, 2025
CVE-2024-12365
8.5 HIGH

The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in …

Jan 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.