CVE Database

Comprehensive vulnerability intelligence with advanced analytics

5.5

CVE-2026-20805

Medium KEV

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

Published: Jan 13, 2026
Modified: Jan 14, 2026
Product: microsoft windows_server_2019
EPSS: 23.28%
View Details
7.5

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior…

Published: Dec 19, 2025
Modified: Jan 13, 2026
EPSS: 57.25%
View Details
9.8

CVE-2025-14733

Critical KEV

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and…

Published: Dec 19, 2025
Modified: Dec 23, 2025
EPSS: 36.33%
View Details
6.6

CVE-2025-40602

Medium KEV

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

Published: Dec 18, 2025
Modified: Dec 19, 2025
EPSS: 1.86%
View Details
8.8

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, tvOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of…

Published: Dec 17, 2025
Modified: Dec 18, 2025
EPSS: 0.05%
View Details
10.0

CVE-2025-20393

Critical KEV

Cisco is aware of a potential vulnerability.  Cisco is currently investigating and will update these details as appropriate as more information becomes available.

Published: Dec 17, 2025
Modified: Dec 18, 2025
EPSS: 7.28%
View Details
9.8

CVE-2025-59374

Critical KEV

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client…

Published: Dec 17, 2025
Modified: Dec 18, 2025
EPSS: 35.96%
View Details
10.0

CVE-2025-37164

Critical KEV

A remote code execution issue exists in HPE OneView.

Published: Dec 16, 2025
Modified: Jan 08, 2026
Product: hpe oneview
EPSS: 81.31%
View Details
9.8

CVE-2025-14611

Critical KEV

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. This opens the door…

Published: Dec 12, 2025
Modified: Dec 16, 2025
EPSS: 39.64%
View Details
8.8

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Published: Dec 12, 2025
Modified: Dec 15, 2025
Product: google chrome
EPSS: 1.72%
View Details
8.8

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

Published: Dec 10, 2025
Modified: Jan 13, 2026
EPSS: 0.95%
View Details
7.8

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Published: Dec 09, 2025
Modified: Dec 10, 2025
Product: microsoft windows_10_22h2
EPSS: 3.27%
View Details
9.8

CVE-2025-59718

Critical KEV

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows…

Published: Dec 09, 2025
Modified: Dec 17, 2025
EPSS: 5.72%
View Details
5.5

CVE-2025-48633

Medium KEV

In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Published: Dec 08, 2025
Modified: Dec 10, 2025
Product: google android
EPSS: 0.16%
View Details
7.8

In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Published: Dec 08, 2025
Modified: Dec 10, 2025
Product: google android
EPSS: 0.26%
View Details
7.2

Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

Published: Dec 05, 2025
Modified: Dec 10, 2025
EPSS: 3.02%
View Details
10.0

CVE-2025-55182

Critical KEV

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Published: Dec 03, 2025
Modified: Dec 10, 2025
Product: vercel next.js
EPSS: 62.33%
View Details
8.2

GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently…

Published: Nov 25, 2025
Modified: Dec 12, 2025
EPSS: 82.60%
View Details
7.2

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the…

Published: Nov 18, 2025
Modified: Nov 21, 2025
Product: fortinet fortiweb
EPSS: 53.94%
View Details
8.8

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Published: Nov 17, 2025
Modified: Dec 02, 2025
Product: google chrome
EPSS: 1.16%
View Details
9.8

CVE-2025-64446

Critical KEV

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Published: Nov 14, 2025
Modified: Nov 21, 2025
Product: fortinet fortiweb
EPSS: 89.81%
View Details
7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

Published: Nov 11, 2025
Modified: Nov 14, 2025
Product: microsoft windows_server_2019
EPSS: 0.67%
View Details
9.1

CVE-2025-12480

Critical KEV

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

Published: Nov 10, 2025
Modified: Nov 14, 2025
Product: gladinet triofox
EPSS: 74.17%
View Details
9.8

CVE-2025-61757

Critical KEV

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS…

Published: Oct 21, 2025
Modified: Nov 24, 2025
Product: oracle identity_manager
EPSS: 82.16%
View Details
Page 1 Next