CVE Dashboard

CVE-2021-32030

ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allo...

MEDIUM Published: 2025-06-02
CVE-2025-3935

ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability coul...

MEDIUM Published: 2025-06-02
CVE-2025-35939

Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulner...

MEDIUM Published: 2025-06-02
CVE-2024-56145

Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to re...

MEDIUM Published: 2025-06-02
CVE-2023-39780

ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authen...

MEDIUM Published: 2025-06-02
CVE-2025-4632

Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write...

MEDIUM Published: 2025-05-22
CVE-2023-38950

ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthentica...

MEDIUM Published: 2025-05-19
CVE-2024-27443

Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite featu...

MEDIUM Published: 2025-05-19
CVE-2025-27920

Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to acce...

MEDIUM Published: 2025-05-19
CVE-2024-11182

MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attack...

MEDIUM Published: 2025-05-19
CVE-2025-4428

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component t...

MEDIUM Published: 2025-05-19
CVE-2025-4427

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API com...

MEDIUM Published: 2025-05-19
CVE-2025-42999

SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows...

MEDIUM Published: 2025-05-15
CVE-2024-12987

DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability du...

MEDIUM Published: 2025-05-15
CVE-2025-32756

Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability...

MEDIUM Published: 2025-05-14
CVE-2025-32709

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that...

MEDIUM Published: 2025-05-13
CVE-2025-30397

Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthoriz...

MEDIUM Published: 2025-05-13
CVE-2025-32706

Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnera...

MEDIUM Published: 2025-05-13
CVE-2025-32701

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that...

MEDIUM Published: 2025-05-13
CVE-2025-30400

Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized...

MEDIUM Published: 2025-05-13
CVE-2025-47729

TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend hol...

MEDIUM Published: 2025-05-12
CVE-2024-11120

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unaut...

MEDIUM Published: 2025-05-07
CVE-2024-6047

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unaut...

MEDIUM Published: 2025-05-07
CVE-2025-27363

FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph struct...

MEDIUM Published: 2025-05-06
CVE-2025-3248

Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that...

MEDIUM Published: 2025-05-05
CVE-2025-34028

Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticat...

MEDIUM Published: 2025-05-02
CVE-2024-58136

Yii Framework contains an improper protection of alternate path vulnerability that may allow a remot...

MEDIUM Published: 2025-05-02
CVE-2024-38475

Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows...

MEDIUM Published: 2025-05-01
CVE-2023-44221

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management...

MEDIUM Published: 2025-05-01
CVE-2025-31324

SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability t...

MEDIUM Published: 2025-04-29
CVE-2025-1976

Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with adm...

MEDIUM Published: 2025-04-28
CVE-2025-42599

Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, una...

MEDIUM Published: 2025-04-28
CVE-2025-3928

Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attac...

MEDIUM Published: 2025-04-28
CVE-2025-24054

Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows a...

MEDIUM Published: 2025-04-17
CVE-2025-31201

Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability...

MEDIUM Published: 2025-04-17
CVE-2025-31200

Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that al...

MEDIUM Published: 2025-04-17
CVE-2021-20035

SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interfac...

MEDIUM Published: 2025-04-16
CVE-2024-53150

Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a loca...

MEDIUM Published: 2025-04-09
CVE-2024-53197

Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an a...

MEDIUM Published: 2025-04-09
CVE-2025-29824

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that...

MEDIUM Published: 2025-04-08
CVE-2025-30406

Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the...

MEDIUM Published: 2025-04-08
CVE-2025-31161

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allow...

MEDIUM Published: 2025-04-07
CVE-2025-22457

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulner...

MEDIUM Published: 2025-04-04
CVE-2025-24813

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute cod...

MEDIUM Published: 2025-04-01
CVE-2024-20439

Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthentica...

MEDIUM Published: 2025-03-31
CVE-2025-2783

Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, whi...

MEDIUM Published: 2025-03-27
CVE-2019-9875

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Se...

MEDIUM Published: 2025-03-26
CVE-2019-9874

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Se...

MEDIUM Published: 2025-03-26
CVE-2025-30154

reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps ex...

MEDIUM Published: 2025-03-24
CVE-2017-12637

SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler...

MEDIUM Published: 2025-03-19