Loading HuntDB...

Known Exploited Vulnerabilities

Search through CISA's catalog of actively exploited vulnerabilities

Press Enter to search
173,859 vulnerabilities found
Showing 61 - 80

Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

Added May 19, 2025 CVE-2025-4427
Due Soon

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

Ivanti Endpoint Manager Mobile (EPMM)
Due by June 9, 2025
Catalog 2025.05.19

ZKTeco BioTime Path Traversal Vulnerability

Added May 19, 2025 CVE-2023-38950
Due Soon

ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.

ZKTeco BioTime
Due by June 9, 2025
Catalog 2025.05.19

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Added May 19, 2025 CVE-2024-27443
Due Soon

Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an email message containing a crafted calendar header, leading to the execution of arbitrary JavaScript code.

Synacor Zimbra Collaboration Suite (ZCS)
Due by June 9, 2025
Catalog 2025.05.19

Srimax Output Messenger Directory Traversal Vulnerability

Added May 19, 2025 CVE-2025-27920
Due Soon

Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

Srimax Output Messenger
Due by June 9, 2025
Catalog 2025.05.19

MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability

Added May 19, 2025 CVE-2024-11182
Due Soon

MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message.

MDaemon Email Server
Due by June 9, 2025
Catalog 2025.05.19

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Added May 19, 2025 CVE-2025-4428
Due Soon

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library.

Ivanti Endpoint Manager Mobile (EPMM)
Due by June 9, 2025
Catalog 2025.05.19

Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

Added May 19, 2025 CVE-2025-4427
Due Soon

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

Ivanti Endpoint Manager Mobile (EPMM)
Due by June 9, 2025
Catalog 2025.05.19

ZKTeco BioTime Path Traversal Vulnerability

Added May 19, 2025 CVE-2023-38950
Due Soon

ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.

ZKTeco BioTime
Due by June 9, 2025
Catalog 2025.05.22

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Added May 19, 2025 CVE-2024-27443
Due Soon

Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an email message containing a crafted calendar header, leading to the execution of arbitrary JavaScript code.

Synacor Zimbra Collaboration Suite (ZCS)
Due by June 9, 2025
Catalog 2025.05.22

Srimax Output Messenger Directory Traversal Vulnerability

Added May 19, 2025 CVE-2025-27920
Due Soon

Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

Srimax Output Messenger
Due by June 9, 2025
Catalog 2025.05.22

MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability

Added May 19, 2025 CVE-2024-11182
Due Soon

MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message.

MDaemon Email Server
Due by June 9, 2025
Catalog 2025.05.22

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Added May 19, 2025 CVE-2025-4428
Due Soon

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library.

Ivanti Endpoint Manager Mobile (EPMM)
Due by June 9, 2025
Catalog 2025.05.22

Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

Added May 19, 2025 CVE-2025-4427
Due Soon

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

Ivanti Endpoint Manager Mobile (EPMM)
Due by June 9, 2025
Catalog 2025.05.22

ZKTeco BioTime Path Traversal Vulnerability

Added May 19, 2025 CVE-2023-38950
Due Soon

ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.

ZKTeco BioTime
Due by June 9, 2025
Catalog 2025.05.22

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Added May 19, 2025 CVE-2024-27443
Due Soon

Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an email message containing a crafted calendar header, leading to the execution of arbitrary JavaScript code.

Synacor Zimbra Collaboration Suite (ZCS)
Due by June 9, 2025
Catalog 2025.05.22

Srimax Output Messenger Directory Traversal Vulnerability

Added May 19, 2025 CVE-2025-27920
Due Soon

Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

Srimax Output Messenger
Due by June 9, 2025
Catalog 2025.05.22

MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability

Added May 19, 2025 CVE-2024-11182
Due Soon

MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message.

MDaemon Email Server
Due by June 9, 2025
Catalog 2025.05.22

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Added May 19, 2025 CVE-2025-4428
Due Soon

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library.

Ivanti Endpoint Manager Mobile (EPMM)
Due by June 9, 2025
Catalog 2025.05.22

Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

Added May 19, 2025 CVE-2025-4427
Due Soon

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

Ivanti Endpoint Manager Mobile (EPMM)
Due by June 9, 2025
Catalog 2025.05.22

ZKTeco BioTime Path Traversal Vulnerability

Added May 19, 2025 CVE-2023-38950
Due Soon

ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.

ZKTeco BioTime
Due by June 9, 2025
Catalog 2025.05.22