CVE-2024-53197 | HIGH | 7.8 | 0.03558 | 57.45 | Yes | No | 2025-04-09 | 2025-04-09 | cisa.gov, euvd | Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the syst…Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code. |
CVE-2022-44268 | MEDIUM | 6.5 | 0.89855 | 57.45 | No | Yes | 2023-02-06 | 2025-03-26 | euvd, github, packetstorm | ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have …ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it). |
CVE-2022-23302 | HIGH | 8.8 | 0.63556 | 57.44 | No | No | 2022-01-18 | 2026-05-27 | euvd | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j conf…JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions. |
CVE-2021-22123 | HIGH | 7.6 | 0.7727 | 57.44 | No | No | 2021-06-01 | 2024-10-25 | euvd | An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a r…An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page. |
CVE-2026-20128 | HIGH | 7.5 | 0.06943 | 57.43 | Yes | No | 2026-04-20 | 2026-04-20 | cisa.gov, euvd | Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacke…Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user. |
CVE-2023-28342 | HIGH | 7.5 | 0.78338 | 57.42 | No | No | 2023-04-05 | 2025-02-13 | euvd | Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API. |
CVE-2018-0159 | HIGH | 7.5 | 0.06915 | 57.42 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Softwa…A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. |
CVE-2019-1315 | HIGH | 7.8 | 0.03478 | 57.42 | Yes | No | 2022-03-15 | 2022-03-15 | cisa.gov, euvd | A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully…A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. |
CVE-2018-8406 | HIGH | 7.8 | 0.03444 | 57.41 | Yes | No | 2022-03-28 | 2022-03-28 | cisa.gov, euvd | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. |
CVE-2018-8405 | HIGH | 7.8 | 0.03444 | 57.41 | Yes | No | 2022-03-28 | 2022-03-28 | cisa.gov, euvd | An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory. |
CVE-2020-14841 | CRITICAL | 9.8 | 0.52032 | 57.41 | No | No | 2020-10-21 | 2024-09-26 | euvd | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are …Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). |
CVE-2018-7358 | MEDIUM | 6.5 | 0.89645 | 57.38 | No | No | 2018-11-14 | 2024-08-05 | euvd | ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerab…ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper change control vulnerability, which may allow an unauthorized user to perform unauthorized operations. |
CVE-2013-2596 | HIGH | 7.8 | 0.03373 | 57.38 | Yes | No | 2022-09-15 | 2022-09-15 | cisa.gov, euvd | Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation.Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation. |
CVE-2024-53104 | HIGH | 7.8 | 0.03301 | 57.36 | Yes | Yes | 2025-02-05 | 2025-02-05 | cisa.gov, euvd, github | Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that cou…Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege. |
CVE-2022-32894 | HIGH | 7.8 | 0.03286 | 57.35 | Yes | No | 2022-08-18 | 2022-08-18 | cisa.gov, euvd | Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges.Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges. |
CVE-2020-0041 | HIGH | 7.8 | 0.03246 | 57.34 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allo…Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu." |
CVE-2021-36955 | HIGH | 7.8 | 0.03229 | 57.33 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2023-2915 | HIGH | 7.5 | 0.78093 | 57.33 | No | No | 2023-08-17 | 2024-10-08 | euvd | The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, …The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a certain function. If exploited, an unauthenticated remote threat actor can delete arbitrary files with system privileges. A malicious user could exploit this vulnerability by sending a specifically crafted synchronization protocol message resulting in a denial-of-service condition. |
CVE-2017-0022 | MEDIUM | 6.5 | 0.18069 | 57.32 | Yes | No | 2022-05-24 | 2022-05-24 | cisa.gov, euvd | Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web sit…Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site. |
CVE-2023-41061 | HIGH | 7.8 | 0.03125 | 57.29 | Yes | No | 2023-09-11 | 2023-09-11 | cisa.gov, euvd | Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafte…Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064. |
CVE-2022-45933 | CRITICAL | 9.8 | 0.51696 | 57.29 | No | No | 2022-11-27 | 2025-04-29 | euvd | KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentic…KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure." |
CVE-2017-0001 | HIGH | 7.8 | 0.03114 | 57.29 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows …The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges |
CVE-2021-43226 | HIGH | 7.8 | 0.03072 | 57.28 | Yes | No | 2025-10-06 | 2025-10-06 | cisa.gov, euvd | Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker …Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms. |
CVE-2021-39312 | HIGH | 7.5 | 0.77944 | 57.28 | No | No | 2021-12-14 | 2025-01-31 | euvd | The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be a…The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file. |
CVE-2020-0638 | HIGH | 7.8 | 0.03042 | 57.26 | Yes | No | 2022-05-23 | 2022-05-23 | cisa.gov, euvd | Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2018-8589 | HIGH | 7.8 | 0.03023 | 57.26 | Yes | No | 2022-05-23 | 2022-05-23 | cisa.gov, euvd | A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this…A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system. |
CVE-2022-41125 | HIGH | 7.8 | 0.03021 | 57.26 | Yes | No | 2022-11-08 | 2022-11-08 | cisa.gov, euvd | Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to…Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. |
CVE-2023-0587 | CRITICAL | 9.1 | 0.59585 | 57.25 | No | No | 2023-02-01 | 2025-03-27 | euvd | A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT mes…A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the SampleSubmission directory (i.e., \PCCSRV\TEMP\SampleSubmission) on the server. The attacker can upload a large number of large files to fill up the file system on which the Apex One server is installed. |
CVE-2024-25111 | HIGH | 8.6 | 0.65254 | 57.24 | No | No | 2024-03-06 | 2025-11-03 | euvd | Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack again…Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker to cause Denial of Service when sending a crafted, chunked, encoded HTTP Message. This bug is fixed in Squid version 6.8. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. There is no workaround for this issue. |
CVE-2023-42916 | MEDIUM | 6.5 | 0.17823 | 57.24 | Yes | No | 2023-12-04 | 2023-12-04 | cisa.gov, euvd | Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when process…Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing. |
CVE-2021-21341 | HIGH | 7.5 | 0.77801 | 57.23 | No | No | 2021-03-22 | 2024-08-03 | euvd | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may all…XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. No user is affected who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16. |
CVE-2018-4344 | HIGH | 7.8 | 0.02908 | 57.22 | Yes | No | 2022-06-27 | 2022-06-27 | cisa.gov, euvd | Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution.Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution. |
CVE-2025-27007 | CRITICAL | 9.8 | 0.5148 | 57.22 | No | No | 2025-05-01 | 2026-04-28 | euvd | Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit…Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82. |
CVE-2023-41992 | HIGH | 7.8 | 0.02918 | 57.22 | Yes | No | 2023-09-25 | 2023-09-25 | cisa.gov, euvd | Apple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerability that allows for local privilege escalation.Apple iOS, iPadOS, macOS, and watchOS contain an unspecified vulnerability that allows for local privilege escalation. |
CVE-2021-30983 | HIGH | 7.8 | 0.02923 | 57.22 | Yes | No | 2022-06-27 | 2022-06-27 | cisa.gov, euvd | Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges.Apple iOS and iPadOS contain a buffer overflow vulnerability that could allow an application to execute code with kernel privileges. |
CVE-2021-41174 | MEDIUM | 6.9 | 0.84607 | 57.21 | No | No | 2021-11-03 | 2024-08-04 | euvd | Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to vis…Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim's browser. The user visiting the malicious link must be unauthenticated and the link must be for a page that contains the login button in the menu bar. The url has to be crafted to exploit AngularJS rendering and contain the interpolation binding for AngularJS expressions. AngularJS uses double curly braces for interpolation binding: {{ }} ex: {{constructor.constructor(‘alert(1)’)()}}. When the user follows the link and the page renders, the login button will contain the original link with a query parameter to force a redirect to the login page. The URL is not validated and the AngularJS rendering engine will execute the JavaScript expression contained in the URL. Users are advised to upgrade as soon as possible. If for some reason you cannot upgrade, you can use a reverse proxy or similar to block access to block the literal string {{ in the path. |
CVE-2021-29505 | HIGH | 7.5 | 0.77735 | 57.21 | No | No | 2021-05-28 | 2025-05-29 | euvd | XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remo…XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17. |
CVE-2024-7314 | CRITICAL | 9.8 | 0.51468 | 57.21 | No | No | 2024-08-02 | 2025-11-22 | euvd | anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to…anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitrary Java on the victim server. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC. |
CVE-2023-6567 | CRITICAL | 9.8 | 0.51394 | 57.19 | No | No | 2024-01-11 | 2026-04-08 | euvd | The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and includ…The LearnPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 4.2.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. |
CVE-2022-24760 | CRITICAL | 10.0 | 0.49081 | 57.18 | No | No | 2022-03-11 | 2025-04-22 | euvd | Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in …Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configuration with MongoDB. The main weakness that leads to RCE is the Prototype Pollution vulnerable code in the file `DatabaseController.js`, so it is likely to affect Postgres and any other database backend as well. This vulnerability has been confirmed on Linux (Ubuntu) and Windows. Users are advised to upgrade as soon as possible. The only known workaround is to manually patch your installation with code referenced at the source GHSA-p6h4-93qp-jhcm. |
CVE-2024-53676 | CRITICAL | 9.8 | 0.51343 | 57.17 | No | No | 2024-11-27 | 2025-03-05 | euvd | A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution. |
CVE-2024-36971 | HIGH | 7.8 | 0.02701 | 57.15 | Yes | No | 2024-08-07 | 2024-08-07 | cisa.gov, euvd | Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kerne…Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS. |
CVE-2021-31979 | HIGH | 7.8 | 0.02634 | 57.12 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. |
CVE-2020-24557 | HIGH | 7.8 | 0.02639 | 57.12 | Yes | No | 2021-11-03 | 2021-11-03 | cisa.gov, euvd | Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability tha…Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation. |
CVE-2023-50224 | MEDIUM | 6.5 | 0.1745 | 57.11 | Yes | No | 2025-09-03 | 2025-09-03 | cisa.gov, euvd | TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by defa…TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. |
CVE-2017-6627 | HIGH | 7.5 | 0.06042 | 57.11 | Yes | No | 2022-03-03 | 2022-03-03 | cisa.gov, euvd | A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue …A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service. |
CVE-2025-59230 | HIGH | 7.8 | 0.02584 | 57.1 | Yes | No | 2025-10-14 | 2025-10-14 | cisa.gov, euvd | Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authori…Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally. |
CVE-2025-48828 | CRITICAL | 9.0 | 0.6025 | 57.09 | No | No | 2025-05-27 | 2025-05-27 | euvd | Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By c…Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025. |
CVE-2025-62221 | HIGH | 7.8 | 0.02416 | 57.05 | Yes | No | 2025-12-09 | 2025-12-09 | cisa.gov, euvd | Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate pr…Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally. |
CVE-2025-11833 | CRITICAL | 9.8 | 0.51005 | 57.05 | No | No | 2025-11-01 | 2026-04-08 | euvd | The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access…The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construct function in all versions up to, and including, 3.6.0. This makes it possible for unauthenticated attackers to read arbitrary logged emails sent through the Post SMTP plugin, including password reset emails containing password reset links, which can lead to account takeover. |