CVE Database

38971+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-62204
8.0 HIGH

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Nov 11, 2025
CVE-2025-62203
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Nov 11, 2025
CVE-2025-62202
7.1 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Nov 11, 2025
CVE-2025-62201
7.8 HIGH

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Nov 11, 2025
CVE-2025-62200
7.8 HIGH

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Nov 11, 2025
CVE-2025-62199
7.8 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Nov 11, 2025
CVE-2025-61836
7.8 HIGH

Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Nov 11, 2025
CVE-2025-61831
7.8 HIGH

Illustrator versions 28.7.10, 29.8.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Nov 11, 2025
CVE-2025-61829
7.8 HIGH

Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-61828
7.8 HIGH

Illustrator on iPad versions 3.0.9 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Nov 11, 2025
CVE-2025-61827
7.8 HIGH

Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-61826
7.8 HIGH

Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Nov 11, 2025
CVE-2025-61820
7.8 HIGH

Illustrator versions 28.7.10, 29.8.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Nov 11, 2025
CVE-2025-61819
7.8 HIGH

Photoshop Desktop versions 26.8.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Nov 11, 2025
CVE-2025-60727
7.8 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Nov 11, 2025
CVE-2025-60726
7.1 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Nov 11, 2025
CVE-2025-60721
7.8 HIGH

Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60720
7.8 HIGH

Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60719
7.0 HIGH

Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60718
7.8 HIGH

Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60717
7.0 HIGH

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60716
7.0 HIGH

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60715
8.0 HIGH

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Nov 11, 2025
CVE-2025-60714
7.8 HIGH

Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.

Nov 11, 2025
CVE-2025-60713
7.8 HIGH

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60710
7.8 HIGH KEV

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60709
7.8 HIGH

Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60707
7.8 HIGH

Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60705
7.8 HIGH

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60704
7.5 HIGH

Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.

Nov 11, 2025
CVE-2025-60703
7.8 HIGH

Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59515
7.0 HIGH

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59514
7.8 HIGH

Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59512
7.8 HIGH

Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59511
7.8 HIGH

External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59508
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59507
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59506
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59505
7.8 HIGH

Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59504
7.3 HIGH

Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

Nov 11, 2025
CVE-2025-59499
8.8 HIGH

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Nov 11, 2025
CVE-2025-30398
8.1 HIGH

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

Nov 11, 2025
CVE-2025-61832
7.8 HIGH

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-61824
7.8 HIGH

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-61818
7.8 HIGH

InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Nov 11, 2025
CVE-2025-61817
7.8 HIGH

InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Nov 11, 2025
CVE-2025-61816
7.8 HIGH

InCopy versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Nov 11, 2025
CVE-2025-61815
7.8 HIGH

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-61814
7.8 HIGH

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-35971
8.2 HIGH

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged …

Nov 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.