CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-24435
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A …

Feb 11, 2025
CVE-2025-24428
5.4 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a …

Feb 11, 2025
CVE-2025-24427
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24426
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24425
5.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Business Logic Error vulnerability that could result in a security feature …

Feb 11, 2025
CVE-2025-24424
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24423
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A …

Feb 11, 2025
CVE-2025-24422
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature …

Feb 11, 2025
CVE-2025-24421
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24420
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24419
4.3 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. …

Feb 11, 2025
CVE-2025-24408
6.5 MEDIUM

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged …

Feb 11, 2025
CVE-2025-21377
6.5 MEDIUM

NTLM Hash Disclosure Spoofing Vulnerability

Feb 11, 2025
CVE-2025-21352
6.5 MEDIUM

Internet Connection Sharing (ICS) Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21350
5.9 MEDIUM

Windows Kerberos Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21349
6.8 MEDIUM

Windows Remote Desktop Configuration Service Tampering Vulnerability

Feb 11, 2025
CVE-2025-21347
6.0 MEDIUM

Windows Deployment Services Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21259
5.3 MEDIUM

Microsoft Outlook Spoofing Vulnerability

Feb 11, 2025
CVE-2025-21254
6.5 MEDIUM

Internet Connection Sharing (ICS) Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21216
6.5 MEDIUM

Internet Connection Sharing (ICS) Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21212
6.5 MEDIUM

Internet Connection Sharing (ICS) Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21188
6.0 MEDIUM

Azure Network Watcher VM Extension Elevation of Privilege Vulnerability

Feb 11, 2025
CVE-2025-21179
4.8 MEDIUM

DHCP Client Service Denial of Service Vulnerability

Feb 11, 2025
CVE-2025-21162
5.5 MEDIUM

Photoshop Elements versions 2025.0 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege …

Feb 11, 2025
CVE-2025-21155
5.5 MEDIUM

Substance3D - Stager versions 3.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Feb 11, 2025
CVE-2019-15002
4.3 MEDIUM

An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an …

Feb 11, 2025
CVE-2025-21126
5.5 MEDIUM

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service condition. An attacker …

Feb 11, 2025
CVE-2025-21125
5.5 MEDIUM

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Feb 11, 2025
CVE-2025-21124
5.5 MEDIUM

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 11, 2025
CVE-2024-52968
6.7 MEDIUM

An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.

Feb 11, 2025
CVE-2024-50569
6.6 MEDIUM

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allows attacker to execute unauthorized …

Feb 11, 2025
CVE-2024-40586
6.7 MEDIUM

An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to …

Feb 11, 2025
CVE-2024-36508
6.0 MEDIUM

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and …

Feb 11, 2025
CVE-2024-33504
4.1 MEDIUM

A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all …

Feb 11, 2025
CVE-2023-40721
6.7 MEDIUM

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.

Feb 11, 2025
CVE-2024-13843
6.0 MEDIUM

Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin …

Feb 11, 2025
CVE-2024-13842
6.0 MEDIUM

A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges …

Feb 11, 2025
CVE-2024-13830
6.1 MEDIUM

Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. …

Feb 11, 2025
CVE-2024-12797
6.3 MEDIUM

Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server was not authenticated, because handshakes …

Feb 11, 2025
CVE-2024-12058
6.8 MEDIUM

External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker …

Feb 11, 2025
CVE-2024-11771
5.3 MEDIUM

Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.

Feb 11, 2025
CVE-2025-26493
4.6 MEDIUM

In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab

Feb 11, 2025
CVE-2025-1231
5.4 MEDIUM

Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password after check-in due …

Feb 11, 2025
CVE-2025-0588
4.9 MEDIUM

In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting …

Feb 11, 2025
CVE-2025-24956
6.2 MEDIUM

A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial …

Feb 11, 2025
CVE-2025-24812
6.5 MEDIUM

A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0) (All versions < V4.7), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0) (All versions < …

Feb 11, 2025
CVE-2025-24532
4.3 MEDIUM

A vulnerability has been identified in SCALANCE WAB762-1 (6GK5762-1AJ00-6AA0) (All versions < V3.0.0), SCALANCE WAM763-1 (6GK5763-1AL00-7DA0) (All versions < V3.0.0), SCALANCE WAM763-1 (ME) (6GK5763-1AL00-7DC0) (All …

Feb 11, 2025
CVE-2025-0862
4.9 MEDIUM

The SuperSaaS – online appointment scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘after’ parameter in all versions up to, and …

Feb 11, 2025
CVE-2025-0526
5.4 MEDIUM

In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked …

Feb 11, 2025
CVE-2025-0513
5.4 MEDIUM

In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error …

Feb 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.