Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-55752 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2025-55752)
vulnerability in org.apache.tomcat:tomcat (CVE-2025-55752). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.0.109, 10.1.45, 11.0.11` or later.
|
| CVE-2025-55754 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2025-55754)
vulnerability in org.apache.tomcat:tomcat (CVE-2025-55754). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.0.109, 10.1.45, 11.0.11` or later.
|
| CVE-2025-34292 |
|
Unsafe Deserialization in deserialization (CVE-2025-34292)
vulnerability in deserialization (CVE-2025-34292). Risk of unauthorized operations or information disclosure. Exploitable via ``formkit_memory_recovery``.
|
| CVE-2025-54236 KEV |
|
[KEV] Vulnerability in Adobe commerce (CVE-2025-54236)
vulnerability in Adobe commerce (CVE-2025-54236). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2025-59287 KEV |
|
[KEV] Unsafe Deserialization in Microsoft windows (CVE-2025-59287)
vulnerability in Microsoft windows (CVE-2025-59287). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-11023 |
|
Vulnerability in CVE-2025-11023 (CVE-2025-11023)
vulnerability in CVE-2025-11023 (CVE-2025-11023). Successful exploitation can lead to full system takeover.
|
| CVE-2025-61932 KEV |
|
[KEV] Vulnerability in Motex lanscope-endpoint-manager (CVE-2025-61932)
vulnerability in Motex lanscope-endpoint-manager (CVE-2025-61932). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-60511 |
|
Vulnerability in CVE-2025-60511 (CVE-2025-60511)
vulnerability in CVE-2025-60511 (CVE-2025-60511). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-33073 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2025-33073)
vulnerability in Microsoft windows (CVE-2025-33073). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-48503 KEV |
|
[KEV] Vulnerability in Apple multiple-products (CVE-2022-48503)
vulnerability in Apple multiple-products (CVE-2022-48503). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-2746 KEV |
|
[KEV] Vulnerability in Kentico xperience-cms (CVE-2025-2746)
vulnerability in Kentico xperience-cms (CVE-2025-2746). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-2747 KEV |
|
[KEV] Vulnerability in Kentico xperience-cms (CVE-2025-2747)
vulnerability in Kentico xperience-cms (CVE-2025-2747). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-61884 KEV |
|
[KEV] Path Traversal in Oracle e-business-suite (CVE-2025-61884)
path traversal in Oracle e-business-suite (CVE-2025-61884). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2025-57567 |
|
Code Injection in CVE-2025-57567 (CVE-2025-57567)
code injection in CVE-2025-57567 (CVE-2025-57567). Successful exploitation can lead to full system takeover.
|
| CVE-2025-60641 |
|
SQL Injection in sqli (CVE-2025-60641)
SQL injection in sqli (CVE-2025-60641). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-34512 |
|
Cross-Site Scripting (XSS) in ilevia (CVE-2025-34512)
cross-site scripting in ilevia (CVE-2025-34512). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-54253 KEV |
|
[KEV] Vulnerability in Adobe experience-manager-aem-forms (CVE-2025-54253)
vulnerability in Adobe experience-manager-aem-forms (CVE-2025-54253). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-59249 |
|
Vulnerability in microsoft (CVE-2025-59249)
vulnerability in microsoft (CVE-2025-59249). Successful exploitation can lead to full system takeover.
|
| CVE-2025-59248 |
|
Vulnerability in microsoft (CVE-2025-59248)
vulnerability in microsoft (CVE-2025-59248). Confidential information can be exposed externally.
|
| CVE-2025-59234 |
|
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
|
| CVE-2025-59227 |
|
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
|
| CVE-2025-53782 |
|
Vulnerability in microsoft (CVE-2025-53782)
vulnerability in microsoft (CVE-2025-53782). Successful exploitation can lead to full system takeover.
|
| CVE-2025-57740 |
|
Vulnerability in fortinet (CVE-2025-57740)
vulnerability in fortinet (CVE-2025-57740). Successful exploitation can lead to full system takeover.
|
| CVE-2025-58903 |
|
Vulnerability in fortinet (CVE-2025-58903)
vulnerability in fortinet (CVE-2025-58903). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-47890 |
|
Open Redirect in fortinet (CVE-2025-47890)
vulnerability in fortinet (CVE-2025-47890). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-31366 |
|
Cross-Site Scripting (XSS) in fortinet (CVE-2025-31366)
cross-site scripting in fortinet (CVE-2025-31366). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-31514 |
|
Vulnerability in fortinet (CVE-2025-31514)
vulnerability in fortinet (CVE-2025-31514). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-25253 |
|
Vulnerability in fortinet (CVE-2025-25253)
vulnerability in fortinet (CVE-2025-25253). Successful exploitation can lead to full system takeover.
|
| CVE-2025-24990 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2025-24990)
vulnerability in Microsoft windows (CVE-2025-24990). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-59230 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2025-59230)
vulnerability in Microsoft windows (CVE-2025-59230). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-47827 KEV |
|
[KEV] Vulnerability in igel (CVE-2025-47827)
vulnerability in igel (CVE-2025-47827). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-7836 KEV |
|
[KEV] Authentication Bypass in Skysea client-view (CVE-2016-7836)
authentication bypass in Skysea client-view (CVE-2016-7836). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-43798 KEV |
|
[KEV] Path Traversal in Grafana labs grafana-labs (CVE-2021-43798)
path traversal in Grafana labs grafana-labs (CVE-2021-43798). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-27915 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Synacor zimbra-collaboration-suite-zcs (CVE-2025-27915)
cross-site scripting in Synacor zimbra-collaboration-suite-zcs (CVE-2025-27915). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-43226 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2021-43226)
vulnerability in Microsoft windows (CVE-2021-43226). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2013-3918 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2013-3918)
vulnerability in Microsoft windows (CVE-2013-3918). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2011-3402 KEV |
|
[KEV] Vulnerability in Microsoft windows (CVE-2011-3402)
vulnerability in Microsoft windows (CVE-2011-3402). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22555 KEV |
|
[KEV] Out-of-Bounds Write in Linux kernel (CVE-2021-22555)
out-of-bounds write in Linux kernel (CVE-2021-22555). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2010-3765 KEV |
|
[KEV] Vulnerability in Mozilla multiple-products (CVE-2010-3765)
vulnerability in Mozilla multiple-products (CVE-2010-3765). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-61882 KEV |
|
[KEV] Authentication Bypass in Oracle e-business-suite (CVE-2025-61882)
authentication bypass in Oracle e-business-suite (CVE-2025-61882). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2010-3962 KEV |
|
[KEV] Vulnerability in Microsoft internet-explorer (CVE-2010-3962)
vulnerability in Microsoft internet-explorer (CVE-2010-3962). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-22862 |
|
Vulnerability in fortinet (CVE-2025-22862)
vulnerability in fortinet (CVE-2025-22862). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1000353 KEV |
|
[KEV] Vulnerability in jenkins (CVE-2017-1000353)
vulnerability in jenkins (CVE-2017-1000353). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-21043 KEV |
|
[KEV] Out-of-Bounds Write in Samsung mobile-devices (CVE-2025-21043)
out-of-bounds write in Samsung mobile-devices (CVE-2025-21043). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2014-6278 KEV |
|
[KEV] OS Command Injection in gnu (CVE-2014-6278)
OS command injection in gnu (CVE-2014-6278). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2015-7755 KEV |
|
[KEV] Authentication Bypass in Juniper screenos (CVE-2015-7755)
authentication bypass in Juniper screenos (CVE-2015-7755). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-4008 KEV |
|
[KEV] Vulnerability in Smartbedded meteobridge (CVE-2025-4008)
vulnerability in Smartbedded meteobridge (CVE-2025-4008). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-32463 KEV |
|
[KEV] Vulnerability in sudo (CVE-2025-32463)
vulnerability in sudo (CVE-2025-32463). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-59689 KEV |
|
[KEV] Command Injection in Libraesva email-security-gateway (CVE-2025-59689)
command injection in Libraesva email-security-gateway (CVE-2025-59689). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-10035 KEV |
|
[KEV] Command Injection in Fortra goanywhere-mft (CVE-2025-10035)
command injection in Fortra goanywhere-mft (CVE-2025-10035). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|