CVE Database

115581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-22893
7.8 HIGH

Insufficient control flow management in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially …

Aug 12, 2025
CVE-2025-22889
7.9 HIGH

Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processor with Intel(R) TDX may allow a privileged user to potentially enable …

Aug 12, 2025
CVE-2025-22853
2.3 LOW

Improper synchronization in the firmware for some Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

Aug 12, 2025
CVE-2025-22840
7.4 HIGH

Sequence of processor instructions leads to unexpected behavior for some Intel(R) Xeon(R) 6 Scalable processors may allow an authenticated user to potentially enable escalation of …

Aug 12, 2025
CVE-2025-22839
7.5 HIGH

Insufficient granularity of access control in the OOB-MSM for some Intel(R) Xeon(R) 6 Scalable processors may allow a privileged user to potentially enable escalation of …

Aug 12, 2025
CVE-2025-22838
6.7 MEDIUM

Uncontrolled search path for some Intel(R) RealSense(TM) Dynamic Calibrator software before version 2.14.2.0 may allow an authenticated user to potentially enable escalation of privilege via …

Aug 12, 2025
CVE-2025-22836
7.8 HIGH

Integer overflow or wraparound in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially …

Aug 12, 2025
CVE-2025-22392
4.4 MEDIUM

Out-of-bounds read in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via network access.

Aug 12, 2025
CVE-2025-21096
1.9 LOW

Improper buffer restrictions in the firmware for some Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

Aug 12, 2025
CVE-2025-21093
6.7 MEDIUM

Uncontrolled search path element for some Intel(R) Driver & Support Assistant Tool software before version 24.6.49.8 may allow an authenticated user to potentially enable escalation …

Aug 12, 2025
CVE-2025-21090
6.5 MEDIUM

Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of service via local access.

Aug 12, 2025
CVE-2025-21086
7.5 HIGH

Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable …

Aug 12, 2025
CVE-2025-20627
6.7 MEDIUM

Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.1 may allow an authenticated user to potentially enable escalation of privilege via …

Aug 12, 2025
CVE-2025-20625
7.4 HIGH

Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.110.0.5 may allow an unauthenticated user to potentially enable denial of service …

Aug 12, 2025
CVE-2025-20613
3.3 LOW

Predictable Seed in Pseudo-Random Number Generator (PRNG) in the firmware for some Intel(R) TDX may allow an authenticated user to potentially enable information disclosure via …

Aug 12, 2025
CVE-2025-20109
7.8 HIGH

Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via …

Aug 12, 2025
CVE-2025-20099
6.7 MEDIUM

Improper access control for some Intel(R) Rapid Storage Technology installation software may allow an authenticated user to potentially enable escalation of privilege via local access.

Aug 12, 2025
CVE-2025-20093
8.2 HIGH

Improper check for unusual or exceptional conditions in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated …

Aug 12, 2025
CVE-2025-20092
6.7 MEDIUM

Uncontrolled search path for some Clock Jitter Tool software before version 6.0.1 may allow an authenticated user to potentially enable escalation of privilege via local …

Aug 12, 2025
CVE-2025-20090
5.5 MEDIUM

Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authenticated user to potentially enable denial of service via local …

Aug 12, 2025
CVE-2025-20087
6.7 MEDIUM

Incorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

Aug 12, 2025
CVE-2025-20077
5.3 MEDIUM

Missing release of memory after effective lifetime in the UEFI OobRasMmbiHandlerDriver module for some Intel(R) reference server platforms may allow a privileged user to enable …

Aug 12, 2025
CVE-2025-20074
7.8 HIGH

Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potentially enable escalation of …

Aug 12, 2025
CVE-2025-20067
6.0 MEDIUM

Observable timing discrepancy in firmware for some Intel(R) CSME and Intel(R) SPS may allow a privileged user to potentially enable information disclosure via local access.

Aug 12, 2025
CVE-2025-20053
7.2 HIGH

Improper buffer restrictions for some Intel(R) Xeon(R) Processor firmware with SGX enabled may allow a privileged user to potentially enable escalation of privilege via local …

Aug 12, 2025
CVE-2025-20048
6.7 MEDIUM

Uncontrolled search path for the Intel(R) Trace Analyzer and Collector software all verions may allow an authenticated user to potentially enable escalation of privilege via …

Aug 12, 2025
CVE-2025-20037
7.2 HIGH

Time-of-check time-of-use race condition in firmware for some Intel(R) Converged Security and Management Engine may allow a privileged user to potentially enable escalation of privilege …

Aug 12, 2025
CVE-2025-20025
4.4 MEDIUM

Uncontrolled recursion for some TinyCBOR libraries maintained by Intel(R) before version 0.6.1 may allow an authenticated user to potentially enable denial of service via local …

Aug 12, 2025
CVE-2025-20023
6.7 MEDIUM

Incorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

Aug 12, 2025
CVE-2025-20017
6.7 MEDIUM

Uncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated user to potentially enable escalation of privilege via local …

Aug 12, 2025
CVE-2024-33607
5.6 MEDIUM

Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user to potentially enable information disclosure via local access.

Aug 12, 2025
CVE-2025-8452
4.3 MEDIUM

By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-function printers that implement the Brother-provided firmware. …

Aug 12, 2025
CVE-2025-55164

content-security-policy-parser parses content security policy directives. A prototype pollution vulnerability exists in versions 0.5.0 and earlier, wherein if a policy name is called __proto__, one …

Aug 12, 2025
CVE-2025-55011
6.4 MEDIUM

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskFile method in the API does not validate whether …

Aug 12, 2025
CVE-2025-55010
9.1 CRITICAL

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in the ProjectEventActvityFormatter allows admin users …

Aug 12, 2025
CVE-2025-54864
7.5 HIGH

Hydra is a continuous integration service for Nix based projects. Prior to commit f7bda02, /api/push-github and /api/push-gitea are called by the corresponding forge without HTTP …

Aug 12, 2025
CVE-2025-54800
6.1 MEDIUM

Hydra is a continuous integration service for Nix based projects. Prior to commit dea1e16, a malicious package can introduce arbitrary JavaScript code into the Hydra …

Aug 12, 2025
CVE-2025-3089

ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could allow a low privileged user to …

Aug 12, 2025
CVE-2025-38500
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing collect_md xfrm interface collect_md property on xfrm interfaces can …

Aug 12, 2025
CVE-2025-8310
6.5 MEDIUM

Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts …

Aug 12, 2025
CVE-2025-8297
7.2 HIGH

Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to achieve remote code execution

Aug 12, 2025
CVE-2025-8296
7.2 HIGH

SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this …

Aug 12, 2025
CVE-2025-5468
5.5 MEDIUM

Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and …

Aug 12, 2025
CVE-2025-5466
4.9 MEDIUM

XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access …

Aug 12, 2025
CVE-2025-5462
7.5 HIGH

A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons …

Aug 12, 2025
CVE-2025-5456
7.5 HIGH

A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons …

Aug 12, 2025
CVE-2025-3831
8.1 HIGH

Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.

Aug 12, 2025
CVE-2024-38805
6.3 MEDIUM

EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability …

Aug 12, 2025
CVE-2025-22834
4.2 MEDIUM

AMI APTIOV contains a vulnerability in BIOS where a user may cause “Improper Initialization” by local accessing. Successful exploitation of this vulnerability may leave the …

Aug 12, 2025
CVE-2025-22830
6.7 MEDIUM

APTIOV contains a vulnerability in BIOS where a skilled user may cause “Race Condition” by local access. A successful exploitation of this vulnerability may lead …

Aug 12, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.