CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2025-32722

    Last Modified: 20 Feb 2026

    Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    7.3
    High

    CVE-2025-32721

    Last Modified: 26 Feb 2026

    Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-32720

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-32719

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-32718

    Last Modified: 26 Feb 2026

    Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-32716

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.

    Published: 10 Jun 2025
    6.5
    Medium

    CVE-2025-32715

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-32714

    Last Modified: 20 Feb 2026

    Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-32713

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-32712

    Last Modified: 26 Feb 2026

    Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

    Published: 10 Jun 2025
    8.1
    High

    CVE-2025-32710

    Last Modified: 20 Feb 2026

    Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

    Published: 10 Jun 2025
    8.1
    High

    CVE-2025-29828

    Last Modified: 26 Feb 2026

    Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.

    Published: 10 Jun 2025
    8.4
    High

    CVE-2025-47957

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 10 Jun 2025
    1.9
    Low

    CVE-2025-5970

    Last Modified: 23 Jun 2025

    A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 10 Jun 2025
    7.6
    High

    CVE-2024-43706

    Last Modified: 1 Oct 2025

    Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.

    Published: 10 Jun 2025
    5.9
    Medium

    CVE-2024-50568

    Last Modified: 25 Jul 2025

    A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests.

    Published: 10 Jun 2025
    4.3
    Medium

    CVE-2025-25250

    Last Modified: 23 Jun 2026

    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiSASE 25.1.c may allow an authenticated user to access full SSL-VPN settings via crafted URL.

    Published: 10 Jun 2025
    3.2
    Low

    CVE-2023-29184

    Last Modified: 24 Jul 2025

    An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests.

    Published: 10 Jun 2025
    4.3
    Medium

    CVE-2023-48786

    Last Modified: 16 Jul 2025

    A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.

    Published: 10 Jun 2025
    6.5
    Medium

    CVE-2025-24471

    Last Modified: 9 Jun 2026

    An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate.

    Published: 10 Jun 2025
    6.6
    Medium

    CVE-2025-22254

    Last Modified: 26 Feb 2026

    An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiWeb 7.6.0 through 7.6.1, FortiWeb 7.4.0 through 7.4.6 allows an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module.

    Published: 10 Jun 2025
    6.3
    Medium

    CVE-2025-22256

    Last Modified: 24 Jul 2025

    A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests

    Published: 10 Jun 2025
    4.8
    Medium

    CVE-2024-32119

    Last Modified: 16 Jul 2025

    An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.

    Published: 10 Jun 2025
    7.2
    High

    CVE-2025-31104

    Last Modified: 31 Aug 2026

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiADC 7.6.0 through 7.6.1, FortiADC 7.4.0 through 7.4.6, FortiADC 7.2.0 through 7.2.7, FortiADC 7.1.0 through 7.1.4, FortiADC 7.0 all versions, FortiADC 6.2 all versions, FortiADC 6.1 all versions, FortiADC 6.0 all versions, FortiADC 5.4 all versions, FortiADC 5.3 all versions, FortiADC 5.2 all versions, FortiADC 5.1 all versions, FortiADC 5.0 all versions, FortiADC 4.8 all versions, FortiADC 4.7 all versions, FortiADC 4.6 all versions, FortiADC 4.5 all versions, FortiADC 4.4 all versions, FortiADC 4.3 all versions, FortiADC 4.2 all versions, FortiADC 4.1 all versions, FortiADC 4.0 all versions, FortiADC 3.2 all versions, FortiADC 3.1 all versions, FortiADC 3.0 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

    Published: 10 Jun 2025
    3.1
    Low

    CVE-2025-22251

    Last Modified: 25 Jul 2025

    An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.

    Published: 10 Jun 2025
    4.8
    Medium

    CVE-2024-50562

    Last Modified: 9 Jun 2026

    An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out.

    Published: 10 Jun 2025
    4.8
    Medium

    CVE-2024-54019

    Last Modified: 25 Jul 2025

    A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection.

    Published: 10 Jun 2025
    4.3
    Medium

    CVE-2024-45329

    Last Modified: 22 Jul 2025

    A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticated attacker to view unauthorized device information via key modification in API requests.

    Published: 10 Jun 2025
    7.4
    High

    CVE-2025-5969

    Last Modified: 16 Jul 2025

    A vulnerability has been found in D-Link DIR-632 FW103B08 and classified as critical. Affected by this vulnerability is the function FUN_00425fd8 of the file /biurl_grou of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 10 Jun 2025
    8.4
    High

    CVE-2025-33112

    Last Modified: 26 Feb 2026

    IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-47108

    Last Modified: 26 Feb 2026

    Substance3D - Painter versions 11.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-30321

    Last Modified: 16 Jun 2025

    InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-43589

    Last Modified: 26 Feb 2026

    InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-30317

    Last Modified: 26 Feb 2026

    InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-43558

    Last Modified: 26 Feb 2026

    InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-47105

    Last Modified: 16 Jun 2025

    InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-47104

    Last Modified: 16 Jun 2025

    InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-43593

    Last Modified: 26 Feb 2026

    InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-47106

    Last Modified: 16 Jun 2025

    InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-43590

    Last Modified: 26 Feb 2026

    InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 10 Jun 2025
    7.9
    High

    CVE-2023-20599

    Last Modified: 15 Apr 2026

    Improper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto Co-Processor (CCP) registers from x86 resulting in potential loss of control of cryptographic key pointer/index leading to loss of integrity or confidentiality.

    Published: 10 Jun 2025
    5.3
    Medium

    CVE-2025-27206

    Last Modified: 23 Jun 2025

    Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited write access. Exploitation of this issue does not require user interaction.

    Published: 10 Jun 2025
    8.1
    High

    CVE-2025-43586

    Last Modified: 26 Feb 2026

    Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized elevated access. Exploitation of this issue does not require user interaction.

    Published: 10 Jun 2025
    8.4
    High

    CVE-2025-47110

    Last Modified: 15 Jul 2025

    Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Scope is changed to that of other high-privileged accounts, leading to a high impact on confidentiality, integrity, and availability.

    Published: 10 Jun 2025
    6.5
    Medium

    CVE-2025-27207

    Last Modified: 26 Feb 2026

    Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.

    Published: 10 Jun 2025
    8.2
    High

    CVE-2025-43585

    Last Modified: 24 Jun 2025

    Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access leading to a limited impact to confidentiality and a high impact to integrity. Exploitation of this issue does not require user interaction.

    Published: 10 Jun 2025
    7
    High

    CVE-2025-4678

    Last Modified: 15 Apr 2026

    Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue affects Pandora ITSM 5.0.105.

    Published: 10 Jun 2025
    7
    High

    CVE-2025-4653

    Last Modified: 15 Apr 2026

    Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.

    Published: 10 Jun 2025
    6.3
    Medium

    CVE-2025-49143

    Last Modified: 21 Aug 2025

    Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by users to Nautobot's MEDIA_ROOT directory, including DeviceType image attachments as well as images attached to a Location, Device, or Rack, are served to users via a URL endpoint that was not enforcing user authentication. As a consequence, such files can be retrieved by anonymous users who know or can guess the correct URL for a given file. Nautobot v2.4.10 and v1.6.32 address this issue by adding enforcement of Nautobot user authentication to this endpoint.

    Published: 10 Jun 2025
    6
    Medium

    CVE-2025-49142

    Last Modified: 21 Aug 2025

    Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions prior to 2.4.10 or prior to 1.6.32 are potentially affected. Due to insufficient security configuration of the Jinja2 templating feature used in computed fields, custom links, etc. in Nautobot, a malicious user could configure this feature set in ways that could expose the value of Secrets defined in Nautobot when the templated content is rendered or that could call Python APIs to modify data within Nautobot when the templated content is rendered, bypassing the object permissions assigned to the viewing user. Nautobot versions 1.6.32 and 2.4.10 will include fixes for the vulnerability. The vulnerability can be partially mitigated by configuring object permissions appropriately to limit certain actions to only trusted users.

    Published: 10 Jun 2025