CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-49555
8.1 HIGH

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege …

Aug 12, 2025
CVE-2025-49554
7.5 HIGH

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. …

Aug 12, 2025
CVE-2025-48807
6.7 MEDIUM

Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.

Aug 12, 2025
CVE-2025-47954
8.8 HIGH

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Aug 12, 2025
CVE-2025-33051
7.5 HIGH

Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

Aug 12, 2025
CVE-2025-25007
5.3 MEDIUM

Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Aug 12, 2025
CVE-2025-25006
5.3 MEDIUM

Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Aug 12, 2025
CVE-2025-25005
6.5 MEDIUM

Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

Aug 12, 2025
CVE-2025-24999
8.8 HIGH

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Aug 12, 2025
CVE-2025-20044
4.1 MEDIUM

Improper locking for some Intel(R) TDX Module firmware before version 1.5.13 may allow a privileged user to potentially enable escalation of privilege via local access.

Aug 12, 2025
CVE-2025-55167
9.8 CRITICAL

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a SQL Injection vulnerability …

Aug 12, 2025
CVE-2025-55166

savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method only searches for lower-case attribute name, which allows …

Aug 12, 2025
CVE-2025-49568
5.5 MEDIUM

Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. Exploitation of this …

Aug 12, 2025
CVE-2025-49567
5.5 MEDIUM

Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this …

Aug 12, 2025
CVE-2025-49564
7.8 HIGH

Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Aug 12, 2025
CVE-2025-49563
7.8 HIGH

Illustrator versions 28.7.8, 29.6.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Aug 12, 2025
CVE-2025-32086
7.2 HIGH

Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors when using Intel(R) SGX or Intel(R) TDX may allow …

Aug 12, 2025
CVE-2025-32004
3.9 LOW

Improper input validation in the Intel Edger8r Tool for some Intel(R) SGX SDK may allow an authenticated user to potentially enable escalation of privilege via …

Aug 12, 2025
CVE-2025-27717
6.7 MEDIUM

Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable escalation of privilege via local access

Aug 12, 2025
CVE-2025-27707
2.6 LOW

Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated …

Aug 12, 2025
CVE-2025-27576
2.9 LOW

Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated user to potentially enable denial …

Aug 12, 2025
CVE-2025-27559
6.7 MEDIUM

Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated user to potentially enable escalation of privilege via local …

Aug 12, 2025
CVE-2025-27537
5.5 MEDIUM

Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable escalation …

Aug 12, 2025
CVE-2025-27250
3.5 LOW

Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial …

Aug 12, 2025
CVE-2025-26863
3.8 LOW

Uncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable …

Aug 12, 2025
CVE-2025-26697
3.3 LOW

Uncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable …

Aug 12, 2025
CVE-2025-26472
5.7 MEDIUM

Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial …

Aug 12, 2025
CVE-2025-26470
6.7 MEDIUM

Incorrect default permissions for some Intel(R) Distribution for Python software installers before version 2025.1.0 may allow an authenticated user to potentially enable escalation of privilege …

Aug 12, 2025
CVE-2025-26404
6.7 MEDIUM

Uncontrolled search path for some Intel(R) DSA software before version 25.2.15.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

Aug 12, 2025
CVE-2025-26403
7.2 HIGH

Out-of-bounds write in the memory subsystem for some Intel(R) Xeon(R) 6 processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to …

Aug 12, 2025
CVE-2025-25273
7.8 HIGH

Insufficient control flow management in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially …

Aug 12, 2025
CVE-2025-24923
6.7 MEDIUM

Uncontrolled search path in some Intel(R) AI for Enterprise Retrieval-augmented Generation software may allow an authenticated user to potentially enable escalation of privilege via local …

Aug 12, 2025
CVE-2025-24921
6.6 MEDIUM

Improper neutralization for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated user to potentially enable information disclosure …

Aug 12, 2025
CVE-2025-24840
5.8 MEDIUM

Improper access control for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated user to potentially enable escalation …

Aug 12, 2025
CVE-2025-24835
6.5 MEDIUM

Protection mechanism failure in the Intel(R) Graphics Driver for the Intel(R) Arc(TM) B-Series graphics before version 32.0.101.6737 may allow an authenticated user to potentially enable …

Aug 12, 2025
CVE-2025-24523
3.5 LOW

Protection mechanism failure for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial …

Aug 12, 2025
CVE-2025-24520
3.3 LOW

Insertion of sensitive information into log file for some Intel(R) Local Manageability Service software before version 2514.7.16.0 may allow an authenticated user to potentially enable …

Aug 12, 2025
CVE-2025-24515
6.5 MEDIUM

NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.

Aug 12, 2025
CVE-2025-24511
3.3 LOW

Improper initialization in the Linux kernel-mode driver for some Intel(R) I350 Series Ethernet before version 5.19.2 may allow an authenticated user to potentially enable Information …

Aug 12, 2025
CVE-2025-24486
7.8 HIGH

Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable …

Aug 12, 2025
CVE-2025-24484
7.8 HIGH

Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable …

Aug 12, 2025
CVE-2025-24325
8.8 HIGH

Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable …

Aug 12, 2025
CVE-2025-24324
2.8 LOW

Integer overflow or wraparound in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially …

Aug 12, 2025
CVE-2025-24323
6.5 MEDIUM

Improper access control in some firmware package and LED mode toggle tool for some Intel(R) PCIe Switch software before version MR4_1.0b1 may allow a privileged …

Aug 12, 2025
CVE-2025-24313
4.4 MEDIUM

Improper access control for some Device Plugins for Kubernetes software maintained by Intel before version 0.32.0 may allow a privileged user to potentially enable denial …

Aug 12, 2025
CVE-2025-24305
7.2 HIGH

Insufficient control flow management in the Alias Checking Trusted Module (ACTM) firmware for some Intel(R) Xeon(R) processors may allow a privileged user to potentially enable …

Aug 12, 2025
CVE-2025-24303
7.8 HIGH

Improper check for unusual or exceptional conditions in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated …

Aug 12, 2025
CVE-2025-24302
6.7 MEDIUM

Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticated user to potentially enable escalation of privilege via local …

Aug 12, 2025
CVE-2025-24296
6.0 MEDIUM

Improper input validation in some firmware for the Intel(R) E810 Ethernet before version 4.6 may allow a privileged user to enable denial of service via …

Aug 12, 2025
CVE-2025-23241
7.3 HIGH

Integer overflow or wraparound in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially …

Aug 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.