Loading HuntDB...

Known Exploited Vulnerabilities

Search through CISA's catalog of actively exploited vulnerabilities

Press Enter to search
172,499 vulnerabilities found
Showing 1 - 20

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Added June 5, 2025 CVE-2025-5419
Due Soon

Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Google Chromium V8
Due by June 26, 2025
Catalog 2025.06.05

Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Added June 3, 2025 CVE-2025-21479
Due Soon

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

Qualcomm Multiple Chipsets
Due by June 24, 2025
Catalog 2025.06.05

Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Added June 3, 2025 CVE-2025-21479
Due Soon

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

Qualcomm Multiple Chipsets
Due by June 24, 2025
Catalog 2025.06.03

Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

Added June 3, 2025 CVE-2025-21479
Due Soon

Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

Qualcomm Multiple Chipsets
Due by June 24, 2025
Catalog 2025.06.03

ASUS RT-AX55 Routers OS Command Injection Vulnerability

Added June 2, 2025 CVE-2023-39780
Due Soon

ASUS RT-AX55 devices contain a OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands.

ASUS RT-AX55 Routers
Due by June 23, 2025
Catalog 2025.06.05

Craft CMS Code Injection Vulnerability

Added June 2, 2025 CVE-2024-56145
Due Soon

Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.

Craft CMS Craft CMS
Due by June 23, 2025
Catalog 2025.06.05

Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

Added June 2, 2025 CVE-2025-35939
Due Soon

Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a known local file location on the server. This vulnerability could be chained with CVE-2024-58136 as represented by CVE-2025-32432.

Craft CMS Craft CMS
Due by June 23, 2025
Catalog 2025.06.05

ConnectWise ScreenConnect Improper Authentication Vulnerability

Added June 2, 2025 CVE-2025-3935
Due Soon

ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys are compromised.

ConnectWise ScreenConnect
Due by June 23, 2025
Catalog 2025.06.05

ASUS Routers Improper Authentication Vulnerability

Added June 2, 2025 CVE-2021-32030
Due Soon

ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

ASUS Routers
Due by June 23, 2025
Catalog 2025.06.05

ASUS RT-AX55 Routers OS Command Injection Vulnerability

Added June 2, 2025 CVE-2023-39780
Due Soon

ASUS RT-AX55 devices contain a OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands.

ASUS RT-AX55 Routers
Due by June 23, 2025
Catalog 2025.06.03

Craft CMS Code Injection Vulnerability

Added June 2, 2025 CVE-2024-56145
Due Soon

Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.

Craft CMS Craft CMS
Due by June 23, 2025
Catalog 2025.06.03

Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

Added June 2, 2025 CVE-2025-35939
Due Soon

Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a known local file location on the server. This vulnerability could be chained with CVE-2024-58136 as represented by CVE-2025-32432.

Craft CMS Craft CMS
Due by June 23, 2025
Catalog 2025.06.03

ConnectWise ScreenConnect Improper Authentication Vulnerability

Added June 2, 2025 CVE-2025-3935
Due Soon

ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys are compromised.

ConnectWise ScreenConnect
Due by June 23, 2025
Catalog 2025.06.03

ASUS Routers Improper Authentication Vulnerability

Added June 2, 2025 CVE-2021-32030
Due Soon

ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

ASUS Routers
Due by June 23, 2025
Catalog 2025.06.03

ASUS Routers Improper Authentication Vulnerability

Added June 2, 2025 CVE-2021-32030
Due Soon

ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

ASUS Routers
Due by June 23, 2025
Catalog 2025.06.02

ConnectWise ScreenConnect Improper Authentication Vulnerability

Added June 2, 2025 CVE-2025-3935
Due Soon

ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys are compromised.

ConnectWise ScreenConnect
Due by June 23, 2025
Catalog 2025.06.02

Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

Added June 2, 2025 CVE-2025-35939
Due Soon

Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a known local file location on the server. This vulnerability could be chained with CVE-2024-58136 as represented by CVE-2025-32432.

Craft CMS Craft CMS
Due by June 23, 2025
Catalog 2025.06.02

Craft CMS Code Injection Vulnerability

Added June 2, 2025 CVE-2024-56145
Due Soon

Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.

Craft CMS Craft CMS
Due by June 23, 2025
Catalog 2025.06.02

ASUS RT-AX55 Routers OS Command Injection Vulnerability

Added June 2, 2025 CVE-2023-39780
Due Soon

ASUS RT-AX55 devices contain a OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands.

ASUS RT-AX55 Routers
Due by June 23, 2025
Catalog 2025.06.02

ASUS Routers Improper Authentication Vulnerability

Added June 2, 2025 CVE-2021-32030
Due Soon

ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

ASUS Routers
Due by June 23, 2025
Catalog 2025.06.03