Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Clear
ID Title
CVE-2025-4632 KEV [KEV] Path Traversal in Samsung magicinfo-9-server (CVE-2025-4632)
path traversal in Samsung magicinfo-9-server (CVE-2025-4632). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-11182 KEV [KEV] Cross-Site Scripting (XSS) in Mdaemon email-server (CVE-2024-11182)
cross-site scripting in Mdaemon email-server (CVE-2024-11182). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-27920 KEV [KEV] Path Traversal in Srimax output-messenger (CVE-2025-27920)
path traversal in Srimax output-messenger (CVE-2025-27920). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2023-38950 KEV [KEV] Path Traversal in Zkteco biotime (CVE-2023-38950)
path traversal in Zkteco biotime (CVE-2023-38950). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-4427 KEV [KEV] Vulnerability in Ivanti endpoint-manager-mobile-epmm (CVE-2025-4427)
vulnerability in Ivanti endpoint-manager-mobile-epmm (CVE-2025-4427). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-27443 KEV [KEV] Cross-Site Scripting (XSS) in Synacor zimbra-collaboration-suite-zcs (CVE-2024-27443)
cross-site scripting in Synacor zimbra-collaboration-suite-zcs (CVE-2024-27443). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-4428 KEV [KEV] Code Injection in Ivanti endpoint-manager-mobile-epmm (CVE-2025-4428)
code injection in Ivanti endpoint-manager-mobile-epmm (CVE-2025-4428). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-42999 KEV [KEV] Unsafe Deserialization in Sap netweaver (CVE-2025-42999)
vulnerability in Sap netweaver (CVE-2025-42999). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-12987 KEV [KEV] OS Command Injection in Draytek vigor-routers (CVE-2024-12987)
OS command injection in Draytek vigor-routers (CVE-2024-12987). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-32756 KEV [KEV] Vulnerability in Fortinet multiple-products (CVE-2025-32756)
vulnerability in Fortinet multiple-products (CVE-2025-32756). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-30397 KEV [KEV] Vulnerability in Microsoft windows (CVE-2025-30397)
vulnerability in Microsoft windows (CVE-2025-30397). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-30400 KEV [KEV] Use-After-Free in Microsoft windows (CVE-2025-30400)
vulnerability in Microsoft windows (CVE-2025-30400). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-32701 KEV [KEV] Use-After-Free in Microsoft windows (CVE-2025-32701)
vulnerability in Microsoft windows (CVE-2025-32701). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-32709 KEV [KEV] Use-After-Free in Microsoft windows (CVE-2025-32709)
vulnerability in Microsoft windows (CVE-2025-32709). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-32706 KEV [KEV] Vulnerability in Microsoft windows (CVE-2025-32706)
vulnerability in Microsoft windows (CVE-2025-32706). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-47729 KEV [KEV] Vulnerability in Telemessage tm-sgnl (CVE-2025-47729)
vulnerability in Telemessage tm-sgnl (CVE-2025-47729). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-6047 KEV [KEV] OS Command Injection in Geovision multiple-devices (CVE-2024-6047)
OS command injection in Geovision multiple-devices (CVE-2024-6047). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-11120 KEV [KEV] OS Command Injection in Geovision multiple-devices (CVE-2024-11120)
OS command injection in Geovision multiple-devices (CVE-2024-11120). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-27363 KEV [KEV] Out-of-Bounds Write in freetype (CVE-2025-27363)
out-of-bounds write in freetype (CVE-2025-27363). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-3248 KEV [KEV] Vulnerability in langflow (CVE-2025-3248)
vulnerability in langflow (CVE-2025-3248). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-34028 KEV [KEV] Path Traversal in Commvault command-center (CVE-2025-34028)
path traversal in Commvault command-center (CVE-2025-34028). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-58136 KEV [KEV] Vulnerability in Yiiframework yii (CVE-2024-58136)
vulnerability in Yiiframework yii (CVE-2024-58136). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2023-44221 KEV [KEV] OS Command Injection in Sonicwall sma100-appliances (CVE-2023-44221)
OS command injection in Sonicwall sma100-appliances (CVE-2023-44221). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-38475 KEV [KEV] Vulnerability in Apache http-server (CVE-2024-38475)
vulnerability in Apache http-server (CVE-2024-38475). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-31324 KEV [KEV] Unrestricted File Upload in Sap netweaver (CVE-2025-31324)
vulnerability in Sap netweaver (CVE-2025-31324). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-42599 KEV [KEV] Vulnerability in Qualitia active-mail (CVE-2025-42599)
vulnerability in Qualitia active-mail (CVE-2025-42599). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-1976 KEV [KEV] Code Injection in Broadcom brocade-fabric-os (CVE-2025-1976)
code injection in Broadcom brocade-fabric-os (CVE-2025-1976). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-24054 KEV [KEV] Vulnerability in Microsoft windows (CVE-2025-24054)
vulnerability in Microsoft windows (CVE-2025-24054). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-20035 KEV [KEV] OS Command Injection in Sonicwall sma100-appliances (CVE-2021-20035)
OS command injection in Sonicwall sma100-appliances (CVE-2021-20035). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-53197 KEV [KEV] Out-of-Bounds Write in Linux kernel (CVE-2024-53197)
out-of-bounds write in Linux kernel (CVE-2024-53197). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-53150 KEV [KEV] Out-of-Bounds Read in Linux kernel (CVE-2024-53150)
vulnerability in Linux kernel (CVE-2024-53150). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-29824 KEV [KEV] Use-After-Free in Microsoft windows (CVE-2025-29824)
vulnerability in Microsoft windows (CVE-2025-29824). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-30406 KEV [KEV] Vulnerability in Gladinet centrestack (CVE-2025-30406)
vulnerability in Gladinet centrestack (CVE-2025-30406). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-31161 KEV [KEV] Vulnerability in crushftp (CVE-2025-31161)
vulnerability in crushftp (CVE-2025-31161). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Listed in CISA KEV — actively exploited.
CVE-2025-22457 KEV [KEV] Vulnerability in Ivanti connect-secure (CVE-2025-22457)
vulnerability in Ivanti connect-secure (CVE-2025-22457). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-24813 KEV [KEV] Vulnerability in Apache tomcat (CVE-2025-24813)
vulnerability in Apache tomcat (CVE-2025-24813). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-20439 KEV [KEV] Vulnerability in Cisco smart-licensing-utility (CVE-2024-20439)
vulnerability in Cisco smart-licensing-utility (CVE-2024-20439). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2019-9875 KEV [KEV] Unsafe Deserialization in Sitecore cms-and-experience-platform-xp (CVE-2019-9875)
vulnerability in Sitecore cms-and-experience-platform-xp (CVE-2019-9875). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2019-9874 KEV [KEV] Unsafe Deserialization in Sitecore cms-and-experience-platform-xp (CVE-2019-9874)
vulnerability in Sitecore cms-and-experience-platform-xp (CVE-2019-9874). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-30154 KEV [KEV] Vulnerability in Reviewdog action-setup-github-action (CVE-2025-30154)
vulnerability in Reviewdog action-setup-github-action (CVE-2025-30154). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2017-12637 KEV [KEV] Path Traversal in Sap netweaver (CVE-2017-12637)
path traversal in Sap netweaver (CVE-2017-12637). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-1316 KEV [KEV] OS Command Injection in Edimax ic-7100-ip-camera (CVE-2025-1316)
OS command injection in Edimax ic-7100-ip-camera (CVE-2025-1316). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-48248 KEV [KEV] Vulnerability in Nakivo backup-and-replication (CVE-2024-48248)
vulnerability in Nakivo backup-and-replication (CVE-2024-48248). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-30066 KEV [KEV] Vulnerability in Tj-actions changed-files-github-action (CVE-2025-30066)
vulnerability in Tj-actions changed-files-github-action (CVE-2025-30066). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-24472 KEV [KEV] Vulnerability in Fortinet fortios-and-fortiproxy (CVE-2025-24472)
vulnerability in Fortinet fortios-and-fortiproxy (CVE-2025-24472). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-21590 KEV [KEV] Vulnerability in Juniper junos-os (CVE-2025-21590)
vulnerability in Juniper junos-os (CVE-2025-21590). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-24201 KEV [KEV] Out-of-Bounds Write in Apple multiple-products (CVE-2025-24201)
out-of-bounds write in Apple multiple-products (CVE-2025-24201). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-24993 KEV [KEV] Vulnerability in Microsoft windows (CVE-2025-24993)
vulnerability in Microsoft windows (CVE-2025-24993). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-26633 KEV [KEV] Vulnerability in Microsoft windows (CVE-2025-26633)
vulnerability in Microsoft windows (CVE-2025-26633). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-24985 KEV [KEV] Vulnerability in Microsoft windows (CVE-2025-24985)
vulnerability in Microsoft windows (CVE-2025-24985). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →