CVE Database

38971+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-55677
7.8 HIGH

Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-55340
7.0 HIGH

Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.

Oct 14, 2025
CVE-2025-55339
7.8 HIGH

Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-55335
7.4 HIGH

Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-55331
7.0 HIGH

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-55328
7.8 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-55326
7.5 HIGH

Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.

Oct 14, 2025
CVE-2025-55247
7.3 HIGH

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-55240
7.3 HIGH

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-53782
8.4 HIGH

Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-53768
7.8 HIGH

Use after free in Xbox allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-53717
7.0 HIGH

Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-53150
7.8 HIGH

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-53139
7.7 HIGH

Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.

Oct 14, 2025
CVE-2025-50175
7.8 HIGH

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-50174
7.0 HIGH

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-50152
7.8 HIGH

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-48004
7.4 HIGH

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-47989
7.0 HIGH

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-37147
7.1 HIGH

A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to …

Oct 14, 2025
CVE-2025-37146
7.2 HIGH

A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to perform remote command execution. Successful …

Oct 14, 2025
CVE-2025-37134
7.2 HIGH

An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor …

Oct 14, 2025
CVE-2025-37133
7.2 HIGH

An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor …

Oct 14, 2025
CVE-2025-37132
7.2 HIGH

An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could …

Oct 14, 2025
CVE-2025-25004
7.3 HIGH

Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-24990
7.8 HIGH KEV

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of …

Oct 14, 2025
CVE-2025-24052
7.8 HIGH

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of …

Oct 14, 2025
CVE-2025-58325
8.2 HIGH

An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may allow …

Oct 14, 2025
CVE-2025-57741
7.8 HIGH

An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local attacker …

Oct 14, 2025
CVE-2025-57740
7.5 HIGH

An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all …

Oct 14, 2025
CVE-2025-49201
8.1 HIGH

A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM …

Oct 14, 2025
CVE-2025-46774
7.5 HIGH

An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and below, 7.0 all versions may allow …

Oct 14, 2025
CVE-2025-25253
7.5 HIGH

An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all …

Oct 14, 2025
CVE-2025-11577
7.6 HIGH

Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these …

Oct 14, 2025
CVE-2024-50571
7.2 HIGH

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9, FortiAnalyzer 7.0.0 through 7.0.13, FortiAnalyzer 6.4 …

Oct 14, 2025
CVE-2024-48891
7.0 HIGH

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 through 7.6.1, 7.5.0 through 7.5.1, 7.4 …

Oct 14, 2025
CVE-2024-33507
7.4 HIGH

An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 …

Oct 14, 2025
CVE-2025-62156
8.1 HIGH

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 contain …

Oct 14, 2025
CVE-2025-5946
7.2 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modules) …

Oct 14, 2025
CVE-2025-10985
7.2 HIGH

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to …

Oct 14, 2025
CVE-2025-10243
7.2 HIGH

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to …

Oct 14, 2025
CVE-2025-10242
7.2 HIGH

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to …

Oct 14, 2025
CVE-2025-47856
7.2 HIGH

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and …

Oct 14, 2025
CVE-2025-33044
7.8 HIGH

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local …

Oct 14, 2025
CVE-2025-22833
7.3 HIGH

APTIOV contains a vulnerability in BIOS where an attacker may cause a Buffer Copy without Checking Size of Input by local accessing. Successful exploitation of …

Oct 14, 2025
CVE-2025-22832
7.8 HIGH

APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data …

Oct 14, 2025
CVE-2025-22831
7.8 HIGH

APTIOV contains a vulnerability in BIOS where an attacker may cause an Out-of-bounds Write by local. Successful exploitation of this vulnerability may lead to data …

Oct 14, 2025
CVE-2025-9068
7.8 HIGH

A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows …

Oct 14, 2025
CVE-2025-9067
7.8 HIGH

A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair …

Oct 14, 2025
CVE-2025-11720
8.1 HIGH

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied …

Oct 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.