Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2025-6218 KEVEPSS 89% RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect… Winrar 7.12+ Fix from $1,9502025-06-21 HIGH 7.5 CVE-2025-5777 KEVEPSS 100% Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Prox… Netscaler Application Delivery Controller 12.1-55.328 / 13.1-37.235+ Fix from $1,9502025-06-17 HIGH 8.8 CVE-2025-33073 KEVEPSS 80% Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. Windows 10 1507 10.0.10240.21034 / 10.0.14393.8148+ Fix from $1,9502025-06-10 HIGH 8.8 CVE-2025-33053 KEVEPSS 85% External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.21034 / 10.0.14393.8148+ Fix from $1,9502025-06-10 HIGH 8.6 CVE-2025-21479 KEV Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. Aqt1000 Firmware No fix yet Fix from $1,9502025-06-03 HIGH 7.5 CVE-2025-27038 KEV Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. Ar8031 Firmware Mitigation only Fix from $1,9502025-06-03 HIGH 8.6 CVE-2025-21480 KEV Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. Aqt1000 Firmware Mitigation only Fix from $1,9502025-06-03 HIGH 8.8 CVE-2025-5419 KEVEPSS 8% Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a cra… Chrome 137.0.3296.62 / 137.0.7151.68+ Fix from $1,9502025-06-03 CRITICAL 9.0 CVE-2025-5086 KEVEPSS 90% A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code executio… Delmia Apriso after 2025 Fix from $2,3002025-06-02 HIGH 8.8 CVE-2025-49113 KEVEPSS 98% Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n… Debian Linux 1.5.10 / 1.6.11+ Fix from $1,9502025-06-02 MEDIUM 5.3 CVE-2025-48927 KEVEPSS 9% The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the… Telemessage Mitigation only Fix from $1,6002025-05-28 HIGH 7.5 CVE-2025-34026 KEVEPSS 83% The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at at… Concerto 12.1.2+ Fix from $1,9502025-05-21 HIGH 8.8 CVE-2025-4008 KEVEPSS 94% The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system thro… Meteobridge Vm 6.2+ Fix from $1,9502025-05-21 HIGH 7.8 CVE-2025-32709 KEV Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-32706 KEV Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-32701 KEV Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-30400 KEV Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7314 / 10.0.19044.5854+ Fix from $1,9502025-05-13 HIGH 7.5 CVE-2025-30397 KEVEPSS 27% Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a ne… Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 HIGH 8.8 CVE-2025-4428 KEVEPSS 86% Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers t… Endpoint Manager Mobile 11.12.0.5 / 12.3.0.2+ Fix from $1,9502025-05-13 HIGH 7.5 CVE-2025-4427 KEVEPSS 100% An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources wit… Endpoint Manager Mobile 11.12.0.5 / 12.3.0.2+ Fix from $1,9502025-05-13 CRITICAL 9.8 CVE-2025-32756 KEVEPSS 30% A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiC… Fortimail 6.4.6 / 6.4.11+ Fix from $2,3002025-05-13 CRITICAL 9.8 CVE-2025-4632 KEVEPSS 24% Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to wr… Magicinfo 9 Server 21.1052.0+ Fix from $2,3002025-05-13 CRITICAL 9.1 CVE-2025-42999 KEVEPSS 12% SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserializ… Netweaver Mitigation only Fix from $2,3002025-05-13 MEDIUM 5.3 CVE-2025-35939 KEV Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an… Craft Cms 4.15.3 / 5.7.5+ Fix from $1,6002025-05-07 CRITICAL 9.8 CVE-2025-2776 KEVEPSS 64% SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing function… Sysaid after 23.3.40 Fix from $2,3002025-05-07 HIGH 7.5 CVE-2025-2775 KEVEPSS 43% SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionali… Sysaid after 23.3.40 Fix from $1,9502025-05-07 HIGH 8.8 CVE-2025-27920 KEV Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in paramete… Output Messenger 2.0.63+ Fix from $1,9502025-05-05 HIGH 7.2 CVE-2025-3935 KEV ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preser… Screenconnect 25.2.4+ Fix from $1,9502025-04-25 HIGH 8.8 CVE-2025-3928 KEV Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory:… Commvault 11.20.217 / 11.28.141+ Fix from $1,9502025-04-25 CRITICAL 10.0 CVE-2025-32432 KEVEPSS 100% Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.1… Craft Cms 3.9.15 / 4.14.15+ Fix from $2,3002025-04-25