🐞 CVE Tracking and Search

Search and filter Common Vulnerabilities and Exposures

← Dashboard CVE Search Exploitation Radar Breaches Trends Industries Vendors MITRE ATT&CK MITRE ATLAS Threat Actors Attack-Tools Alerts Investigations
Search: Time Range:
Sources: Clear All Filters
378,232+
CVEs Tracked
378,232
Exploit Intel
358,051
EPSS Scored
5,202
CISA KEV
2,698
Metasploit Modules
30,385
ExploitDB Entries
61
MITRE ATT&CK Maps
0
Actively Exploited
0
CISA KEV
1
PoC Available
0
Zero-Days
0
Recent Discoveries
0
Most Mentioned

CVE Severity Distribution (Last 30 Days)

Found 11 CVEs in the last 30 days.

CVE-2025-27495 CRITICAL CVSS: 9.8 EPSS: 1.0% CWE-89 T1190
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateTrace' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25911)
Published: 2025-04-16
CVE-2025-27494 CRITICAL CVSS: 9.1 EPSS: 0.5% CWE-20 T1190
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize input for the pubkey endpoint of the REST API. This could allow an authenticated remote administrator to escalate privileges by injecting arbitrary commands that are executed with root privileges.
Published: 2025-03-11
CVE-2025-27493 HIGH CVSS: 8.2 EPSS: 0.2% CWE-20 T1190
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize user input for specific commands on the telnet command line interface. This could allow an authenticated local administrator to escalate privileges by injecting arbitrary commands that are executed with root privileges.
Published: 2025-03-11
CVE-2025-27490 HIGH CVSS: 7.8 EPSS: 0.6% CWE-122 CWE-125 T1005 T1203
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Published: 2025-04-08
CVE-2025-2749 HIGH CVSS: 7.2 EPSS: 4.0% VulnCheck KEV PoC Available CWE-22 CWE-434 T1083 T1105
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.
Published: 2025-03-24
CVE-2025-27491 HIGH CVSS: 7.1 EPSS: 1.5% CWE-416 T1203
Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.
Published: 2025-04-08
CVE-2025-27492 HIGH CVSS: 7.0 EPSS: 0.3% CWE-362 CWE-416 T1068 T1203
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.
Published: 2025-04-08
CVE-2025-27499 MEDIUM CVSS: 6.1 EPSS: 0.3% CWE-79 T1189
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the processa_edicao_socio.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the socio_nome parameter. The injected scripts are stored on the server and executed automatically whenever the affected page is accessed by users, posing a significant security risk. This vulnerability is fixed in 3.2.10.
Published: 2025-03-03
CVE-2025-27496 LOW CVSS: 3.3 EPSS: 0.1% CWE-532 T1552
Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3.23.0 of the driver. When the logging level was set to DEBUG, the Driver would log locally the client-side encryption master key of the target stage during the execution of GET/PUT commands. This key by itself does not grant access to any sensitive data without additional access authorizations, and is not logged server-side by Snowflake. Snowflake fixed the issue in version 3.23.1.
Published: 2025-03-13
CVE-2025-27497 UNKNOWN EPSS: 0.4%
OpenDJ is an LDAPv3 compliant directory service. OpenDJ prior to 4.9.3 contains a denial-of-service (DoS) vulnerability that causes the server to become unresponsive to all LDAP requests without crashing or restarting. This issue occurs when an alias loop exists in the LDAP database. If an ldapsearch request is executed with alias dereferencing set to "always" on this alias entry, the server stops responding to all future requests. Fortunately, the server can be restarted without data corruption. This vulnerability is fixed in 4.9.3.
Published: 2025-03-05
CVE-2025-27498 UNKNOWN EPSS: 0.1%
aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is exposed even if the tag is incorrect. This is because in decrypt_inplace in asconcore.rs, tag verification causes an error to be returned with the plaintext contents still in buffer. The vulnerability is fixed in 0.4.3.
Published: 2025-03-03