CVE Database

54420+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27738
6.5 MEDIUM

Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-27736
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.

Apr 8, 2025
CVE-2025-27735
6.0 MEDIUM

Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

Apr 8, 2025
CVE-2025-27474
6.5 MEDIUM

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-27472
5.4 MEDIUM

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

Apr 8, 2025
CVE-2025-27471
5.9 MEDIUM

Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-27205
5.4 MEDIUM

Adobe Experience Manager Screens versions FP11.3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged …

Apr 8, 2025
CVE-2025-27204
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-27202
5.5 MEDIUM

Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-27201
5.5 MEDIUM

Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Apr 8, 2025
CVE-2025-27187
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-27186
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-27185
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Apr 8, 2025
CVE-2025-27184
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-26681
6.7 MEDIUM

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26676
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-26672
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-26667
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a …

Apr 8, 2025
CVE-2025-26664
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-26651
6.5 MEDIUM

Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26644
5.1 MEDIUM

Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.

Apr 8, 2025
CVE-2025-26637
6.8 MEDIUM

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Apr 8, 2025
CVE-2025-26635
6.5 MEDIUM

Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.

Apr 8, 2025
CVE-2025-25002
6.8 MEDIUM

Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.

Apr 8, 2025
CVE-2025-21203
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-21197
6.5 MEDIUM

Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to …

Apr 8, 2025
CVE-2025-32279
4.3 MEDIUM

Missing Authorization vulnerability in Shahjada Live Forms liveforms.This issue affects Live Forms: from n/a through <= 4.8.5.

Apr 8, 2025
CVE-2025-32211
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet Broadstreet Ads broadstreet allows Stored XSS.This issue affects Broadstreet Ads: from n/a …

Apr 8, 2025
CVE-2025-32164
6.5 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadList m1downloadlist allows Retrieve Embedded Sensitive Data.This issue affects m1.DownloadList: from n/a …

Apr 8, 2025
CVE-2025-30671
6.5 MEDIUM

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Apr 8, 2025
CVE-2025-30670
6.5 MEDIUM

Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access.

Apr 8, 2025
CVE-2025-27442
4.6 MEDIUM

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

Apr 8, 2025
CVE-2025-27441
4.6 MEDIUM

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

Apr 8, 2025
CVE-2025-27085
4.9 MEDIUM

Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote …

Apr 8, 2025
CVE-2025-27084
5.4 MEDIUM

A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting …

Apr 8, 2025
CVE-2024-52981
4.9 MEDIUM

An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.

Apr 8, 2025
CVE-2024-52980
6.5 MEDIUM

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. …

Apr 8, 2025
CVE-2024-52974
6.5 MEDIUM

An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful attack …

Apr 8, 2025
CVE-2025-27079
6.0 MEDIUM

A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to …

Apr 8, 2025
CVE-2025-27078
6.5 MEDIUM

A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating …

Apr 8, 2025
CVE-2025-22465
6.1 MEDIUM

Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in …

Apr 8, 2025
CVE-2025-22464
6.1 MEDIUM

An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to …

Apr 8, 2025
CVE-2025-22459
4.8 MEDIUM

Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic …

Apr 8, 2025
CVE-2025-30150
5.3 MEDIUM

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if …

Apr 8, 2025
CVE-2024-54025
6.7 MEDIUM

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator CLI before version 2.4.6 allows a …

Apr 8, 2025
CVE-2024-52962
5.3 MEDIUM

An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and …

Apr 8, 2025
CVE-2024-46671
6.2 MEDIUM

An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets …

Apr 8, 2025
CVE-2025-2876
5.3 MEDIUM

The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability check …

Apr 8, 2025
CVE-2025-2568
5.3 MEDIUM

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing …

Apr 8, 2025
CVE-2025-30166
4.8 MEDIUM

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. An HTML injection issue allows users with access to the email sending functionality to inject …

Apr 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.