CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-25929
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the component /legacyui/quickReportServlet of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary JavaScript in the context of …

Mar 11, 2025
CVE-2025-25927
6.8 MEDIUM

A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.

Mar 11, 2025
CVE-2025-25925
4.8 MEDIUM

A stored cross-scripting (XSS) vulnerability in Openmrs v2.4.3 Build 0ff0ed allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into …

Mar 11, 2025
CVE-2025-23243
6.5 MEDIUM

NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to data …

Mar 11, 2025
CVE-2025-27591
6.8 MEDIUM

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have …

Mar 11, 2025
CVE-2025-27179
5.5 MEDIUM

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Mar 11, 2025
CVE-2025-27176
5.5 MEDIUM

InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Mar 11, 2025
CVE-2025-27170
5.5 MEDIUM

Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit …

Mar 11, 2025
CVE-2025-27164
5.5 MEDIUM

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Mar 11, 2025
CVE-2025-27163
5.5 MEDIUM

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Mar 11, 2025
CVE-2025-24449
5.5 MEDIUM

Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Mar 11, 2025
CVE-2025-24448
5.5 MEDIUM

Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Mar 11, 2025
CVE-2025-24431
5.5 MEDIUM

Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Mar 11, 2025
CVE-2021-37787
6.5 MEDIUM

The unprivileged administrative interface in ABO.CMS version 5.8 through v.5.9.3 is affected by a SQL Injection vulnerability via a HTTP POST request to the TinyMCE …

Mar 11, 2025
CVE-2025-24997
4.4 MEDIUM

Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.

Mar 11, 2025
CVE-2025-24996
6.5 MEDIUM

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Mar 11, 2025
CVE-2025-24992
5.5 MEDIUM

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.

Mar 11, 2025
CVE-2025-24991
5.5 MEDIUM KEV

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

Mar 11, 2025
CVE-2025-24988
6.6 MEDIUM

Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.

Mar 11, 2025
CVE-2025-24987
6.6 MEDIUM

Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.

Mar 11, 2025
CVE-2025-24986
6.5 MEDIUM

Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-24984
4.6 MEDIUM KEV

Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

Mar 11, 2025
CVE-2025-24071
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

Mar 11, 2025
CVE-2025-24055
4.3 MEDIUM

Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.

Mar 11, 2025
CVE-2025-24054
6.5 MEDIUM KEV

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Mar 11, 2025
CVE-2025-21247
4.3 MEDIUM

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

Mar 11, 2025
CVE-2025-21199
6.7 MEDIUM

Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-0149
6.5 MEDIUM

Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access.

Mar 11, 2025
CVE-2024-56338
4.8 MEDIUM

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to …

Mar 11, 2025
CVE-2025-27602
4.9 MEDIUM

Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via …

Mar 11, 2025
CVE-2025-27601
4.3 MEDIUM

Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior …

Mar 11, 2025
CVE-2025-25747
5.4 MEDIUM

Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the …

Mar 11, 2025
CVE-2024-55597
5.5 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to execute unauthorized code …

Mar 11, 2025
CVE-2024-54026
4.3 MEDIUM

An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 …

Mar 11, 2025
CVE-2024-52960
4.3 MEDIUM

A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at …

Mar 11, 2025
CVE-2024-51322
5.4 MEDIUM

Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /jsp/home.jsp, /jsp/gsfr_feditorHTML.jsp, /servlet/SPVisualZoom, /jsp/gsmd_container.jsp …

Mar 11, 2025
CVE-2024-51320
5.4 MEDIUM

Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servlet/gsdm_fsave_htmltmp, /servlet/gsdm_btlk_openfile components

Mar 11, 2025
CVE-2024-46663
6.7 MEDIUM

A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or …

Mar 11, 2025
CVE-2024-33501
4.2 MEDIUM

Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, …

Mar 11, 2025
CVE-2024-32123
6.7 MEDIUM

Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 …

Mar 11, 2025
CVE-2023-42784
5.6 MEDIUM

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows …

Mar 11, 2025
CVE-2025-2193
5.4 MEDIUM

A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/delete.do of the component …

Mar 11, 2025
CVE-2025-2192
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Stoque Zeev.it 4.24. This affects an unknown part of the file /Login?inpLostSession=1 of the component …

Mar 11, 2025
CVE-2025-25267
6.2 MEDIUM

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected application …

Mar 11, 2025
CVE-2025-25266
6.8 MEDIUM

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0021), Tecnomatix Plant Simulation V2404 (All versions < V2404.0010). The affected application …

Mar 11, 2025
CVE-2024-52285
5.3 MEDIUM

A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-AP (All versions < V6.4.8). Affected devices expose several …

Mar 11, 2025
CVE-2025-27911
6.5 MEDIUM

An issue was discovered in Datalust Seq before 2024.3.13545. Expansion of identifiers in message templates can be used to bypass the system "Event body limit …

Mar 11, 2025
CVE-2025-1434
6.1 MEDIUM

The Spreadsheet view is vulnerable to a XSS attack, where a remote unauthorised attacker can read a limited amount of values or DoS the affected …

Mar 11, 2025
CVE-2024-58102
5.7 MEDIUM

An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consumption when parsing user-supplied queries containing deeply nested …

Mar 11, 2025
CVE-2025-2175
4.3 MEDIUM

A vulnerability was found in libzvbi up to 0.2.43. It has been rated as problematic. Affected by this issue is the function _vbi_strndup_iconv. The manipulation …

Mar 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.