CVE Database

139595+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-62631
5.6 MEDIUM

An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker …

Dec 9, 2025
CVE-2025-62573
7.0 HIGH

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62572
7.8 HIGH

Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62571
7.8 HIGH

Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62570
7.1 HIGH

Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.

Dec 9, 2025
CVE-2025-62569
7.0 HIGH

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62567
5.3 MEDIUM

Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.

Dec 9, 2025
CVE-2025-62565
7.3 HIGH

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62564
7.8 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62563
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62562
7.8 HIGH

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62561
7.8 HIGH

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62560
7.8 HIGH

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62559
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62558
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62557
8.4 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62556
7.8 HIGH

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62555
7.0 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62554
8.4 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62553
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62552
7.8 HIGH

Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62550
8.8 HIGH

Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

Dec 9, 2025
CVE-2025-62549
8.8 HIGH

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Dec 9, 2025
CVE-2025-62474
7.8 HIGH

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62473
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Dec 9, 2025
CVE-2025-62472
7.8 HIGH

Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62470
7.8 HIGH

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62469
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62468
5.5 MEDIUM

Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

Dec 9, 2025
CVE-2025-62467
7.8 HIGH

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62466
7.8 HIGH

Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62465
6.5 MEDIUM

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

Dec 9, 2025
CVE-2025-62464
7.8 HIGH

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62463
6.5 MEDIUM

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

Dec 9, 2025
CVE-2025-62462
7.8 HIGH

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62461
7.8 HIGH

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62458
7.8 HIGH

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62457
7.8 HIGH

Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62456
8.8 HIGH

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.

Dec 9, 2025
CVE-2025-62455
7.8 HIGH

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62454
7.8 HIGH

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62221
7.8 HIGH KEV

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-61258
7.5 HIGH

Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the body length. NOTE: the Supplier indicates …

Dec 9, 2025
CVE-2025-61078
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter …

Dec 9, 2025
CVE-2025-60024
8.8 HIGH

Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 …

Dec 9, 2025
CVE-2025-59923
2.7 LOW

An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow …

Dec 9, 2025
CVE-2025-59810
6.5 MEDIUM

An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 …

Dec 9, 2025
CVE-2025-59808
6.8 MEDIUM

An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR …

Dec 9, 2025
CVE-2025-59719
9.8 CRITICAL

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to …

Dec 9, 2025
CVE-2025-59718
9.8 CRITICAL KEV

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, …

Dec 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.