Loading HuntDB...

Known Exploited Vulnerabilities

Search through CISA's catalog of actively exploited vulnerabilities

Press Enter to search
238,353 vulnerabilities found
Showing 1 - 20

Microsoft SharePoint Improper Authentication Vulnerability

Added July 22, 2025 CVE-2025-49706
Due Soon

Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. The update for CVE-2025-53771 includes more robust protections than the update for CVE-2025-49706.

Microsoft SharePoint
Due by July 23, 2025
Catalog 2025.07.22

Microsoft SharePoint Code Injection Vulnerability

Added July 22, 2025 CVE-2025-49704
Due Soon

Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. The update for CVE-2025-53770 includes more robust protections than the update for CVE-2025-49704.

Microsoft SharePoint
Due by July 23, 2025
Catalog 2025.07.22

CrushFTP Unprotected Alternate Channel Vulnerability

Added July 22, 2025 CVE-2025-54309
Due Soon

CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.

CrushFTP CrushFTP
Due by August 12, 2025
Catalog 2025.07.22

Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

Added July 22, 2025 CVE-2025-6558
Due Soon

Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Google Chromium
Due by August 12, 2025
Catalog 2025.07.22

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

Added July 22, 2025 CVE-2025-2776
Due Soon

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

SysAid SysAid On-Prem
Due by August 12, 2025
Catalog 2025.07.22

SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

Added July 22, 2025 CVE-2025-2775
Due Soon

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

SysAid SysAid On-Prem
Due by August 12, 2025
Catalog 2025.07.22

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Added July 20, 2025 CVE-2025-53770
Overdue

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network.

Microsoft SharePoint
Due by July 21, 2025
Catalog 2025.07.22

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Added July 20, 2025 CVE-2025-53770
Overdue

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network.

Microsoft SharePoint
Due by July 21, 2025
Catalog 2025.07.20

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Added July 20, 2025 CVE-2025-53770
Overdue

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network.

Microsoft SharePoint
Due by July 21, 2025
Catalog 2025.07.20

Fortinet FortiWeb SQL Injection Vulnerability

Added July 18, 2025 CVE-2025-25257
Due Soon

Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Fortinet FortiWeb
Due by August 8, 2025
Catalog 2025.07.22

Fortinet FortiWeb SQL Injection Vulnerability

Added July 18, 2025 CVE-2025-25257
Due Soon

Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Fortinet FortiWeb
Due by August 8, 2025
Catalog 2025.07.20

Fortinet FortiWeb SQL Injection Vulnerability

Added July 18, 2025 CVE-2025-25257
Due Soon

Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Fortinet FortiWeb
Due by August 8, 2025
Catalog 2025.07.18

Fortinet FortiWeb SQL Injection Vulnerability

Added July 18, 2025 CVE-2025-25257
Due Soon

Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Fortinet FortiWeb
Due by August 8, 2025
Catalog 2025.07.18

Fortinet FortiWeb SQL Injection Vulnerability

Added July 18, 2025 CVE-2025-25257
Due Soon

Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

Fortinet FortiWeb
Due by August 8, 2025
Catalog 2025.07.20

Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

Added July 14, 2025 CVE-2025-47812
Due Soon

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

Wing FTP Server Wing FTP Server
Due by August 4, 2025
Catalog 2025.07.22

Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

Added July 14, 2025 CVE-2025-47812
Due Soon

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

Wing FTP Server Wing FTP Server
Due by August 4, 2025
Catalog 2025.07.20

Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

Added July 14, 2025 CVE-2025-47812
Due Soon

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

Wing FTP Server Wing FTP Server
Due by August 4, 2025
Catalog 2025.07.14

Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

Added July 14, 2025 CVE-2025-47812
Due Soon

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

Wing FTP Server Wing FTP Server
Due by August 4, 2025
Catalog 2025.07.14

Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

Added July 14, 2025 CVE-2025-47812
Due Soon

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

Wing FTP Server Wing FTP Server
Due by August 4, 2025
Catalog 2025.07.14

Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

Added July 14, 2025 CVE-2025-47812
Due Soon

Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

Wing FTP Server Wing FTP Server
Due by August 4, 2025
Catalog 2025.07.14