CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-8760
9.8 CRITICAL

A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the …

Aug 13, 2025
CVE-2025-6184
8.8 HIGH

The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter used in …

Aug 13, 2025
CVE-2025-6715
9.8 CRITICAL

The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and …

Aug 13, 2025
CVE-2025-7384
9.8 CRITICAL

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …

Aug 13, 2025
CVE-2025-8891
4.3 MEDIUM

The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation …

Aug 13, 2025
CVE-2025-8491
4.3 MEDIUM

The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due …

Aug 13, 2025
CVE-2025-0818
6.5 MEDIUM

Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible for unauthenticated attackers to …

Aug 13, 2025
CVE-2025-8901
8.8 HIGH

Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a …

Aug 13, 2025
CVE-2025-8882
8.8 HIGH

Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Aug 13, 2025
CVE-2025-8881
6.5 MEDIUM

Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Aug 13, 2025
CVE-2025-8880
8.8 HIGH

Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. …

Aug 13, 2025
CVE-2025-8879
8.8 HIGH

Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of …

Aug 13, 2025
CVE-2025-4410
7.5 HIGH

A buffer overflow vulnerability exists in the module SetupUtility. An attacker with local privileged access can exploit this vulnerability by executeing arbitrary code.

Aug 13, 2025
CVE-2025-4277
7.5 HIGH

Tcg2Smm has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.

Aug 13, 2025
CVE-2025-4276
7.5 HIGH

UsbCoreDxe has a vulnerability which can be used to write arbitrary memory inside SMRAM and execute arbitrary code at SMM level.

Aug 13, 2025
CVE-2025-8395

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 12, 2025
CVE-2025-54238
5.5 MEDIUM

Dimension versions 4.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires …

Aug 12, 2025
CVE-2025-54233
5.5 MEDIUM

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this …

Aug 12, 2025
CVE-2025-54232
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Aug 12, 2025
CVE-2025-54231
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Aug 12, 2025
CVE-2025-54230
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Aug 12, 2025
CVE-2025-54229
7.8 HIGH

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Aug 12, 2025
CVE-2025-49457
9.6 CRITICAL

Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

Aug 12, 2025
CVE-2025-49456
6.2 MEDIUM

Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access.

Aug 12, 2025
CVE-2025-54222
7.8 HIGH

Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Aug 12, 2025
CVE-2025-55171
7.5 HIGH

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, the application does not …

Aug 12, 2025
CVE-2025-55170
6.5 MEDIUM

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a reflected cross-site scripting …

Aug 12, 2025
CVE-2025-55165
8.2 HIGH

Autocaliweb is a web app that offers an interface for browsing, reading, and downloading eBooks using a valid Calibre database. Prior to version 0.8.3, the …

Aug 12, 2025
CVE-2025-54235
5.5 MEDIUM

Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this …

Aug 12, 2025
CVE-2025-54228
5.5 MEDIUM

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this …

Aug 12, 2025
CVE-2025-54227
5.5 MEDIUM

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this …

Aug 12, 2025
CVE-2025-54226
7.8 HIGH

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Aug 12, 2025
CVE-2025-54225
7.8 HIGH

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Aug 12, 2025
CVE-2025-54224
7.8 HIGH

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Aug 12, 2025
CVE-2025-54223
7.8 HIGH

InCopy versions 20.4, 19.5.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Aug 12, 2025
CVE-2025-54221
7.8 HIGH

InCopy versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Aug 12, 2025
CVE-2025-54220
7.8 HIGH

InCopy versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Aug 12, 2025
CVE-2025-54219
7.8 HIGH

InCopy versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Aug 12, 2025
CVE-2025-54218
7.8 HIGH

InCopy versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Aug 12, 2025
CVE-2025-54217
7.8 HIGH

InCopy versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Aug 12, 2025
CVE-2025-54216
7.8 HIGH

InCopy versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Aug 12, 2025
CVE-2025-54215
7.8 HIGH

InCopy versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Aug 12, 2025
CVE-2025-54214
5.5 MEDIUM

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this …

Aug 12, 2025
CVE-2025-54213
7.8 HIGH

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Aug 12, 2025
CVE-2025-54212
7.8 HIGH

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Aug 12, 2025
CVE-2025-54211
7.8 HIGH

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Aug 12, 2025
CVE-2025-54210
7.8 HIGH

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Aug 12, 2025
CVE-2025-54209
7.8 HIGH

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Aug 12, 2025
CVE-2025-54208
7.8 HIGH

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Aug 12, 2025
CVE-2025-54207
7.8 HIGH

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the …

Aug 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.