CVE Database

45905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-60721
7.8 HIGH

Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60720
7.8 HIGH

Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60719
7.0 HIGH

Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60718
7.8 HIGH

Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60717
7.0 HIGH

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60716
7.0 HIGH

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60715
8.0 HIGH

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Nov 11, 2025
CVE-2025-60714
7.8 HIGH

Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.

Nov 11, 2025
CVE-2025-60713
7.8 HIGH

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60710
7.8 HIGH KEV

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60709
7.8 HIGH

Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60707
7.8 HIGH

Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60705
7.8 HIGH

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-60704
7.5 HIGH

Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.

Nov 11, 2025
CVE-2025-60703
7.8 HIGH

Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59515
7.0 HIGH

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59514
7.8 HIGH

Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59512
7.8 HIGH

Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59511
7.8 HIGH

External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59508
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59507
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59506
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59505
7.8 HIGH

Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59504
7.3 HIGH

Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

Nov 11, 2025
CVE-2025-59499
8.8 HIGH

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Nov 11, 2025
CVE-2025-30398
8.1 HIGH

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

Nov 11, 2025
CVE-2025-61832
7.8 HIGH

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-61824
7.8 HIGH

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-61818
7.8 HIGH

InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Nov 11, 2025
CVE-2025-61817
7.8 HIGH

InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Nov 11, 2025
CVE-2025-61816
7.8 HIGH

InCopy versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Nov 11, 2025
CVE-2025-61815
7.8 HIGH

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-61814
7.8 HIGH

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-35971
8.2 HIGH

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged …

Nov 11, 2025
CVE-2025-35967
7.4 HIGH

Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged …

Nov 11, 2025
CVE-2025-35963
7.4 HIGH

Insufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of …

Nov 11, 2025
CVE-2025-33186
8.8 HIGH

NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.

Nov 11, 2025
CVE-2025-33178
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data created by an attacker may cause a code …

Nov 11, 2025
CVE-2025-33029
7.4 HIGH

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged …

Nov 11, 2025
CVE-2025-33000
8.8 HIGH

Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary …

Nov 11, 2025
CVE-2025-32091
8.2 HIGH

Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may allow an escalation of privilege. System software …

Nov 11, 2025
CVE-2025-30255
8.2 HIGH

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged …

Nov 11, 2025
CVE-2025-30185
7.9 HIGH

Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escalation of privilege. System software …

Nov 11, 2025
CVE-2025-27713
7.8 HIGH

Out-of-bounds write for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary …

Nov 11, 2025
CVE-2025-24838
8.8 HIGH

Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary …

Nov 11, 2025
CVE-2025-24299
8.8 HIGH

Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary …

Nov 11, 2025
CVE-2025-23361
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attacker may cause improper control of code …

Nov 11, 2025
CVE-2025-23357
7.8 HIGH

NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injection issue. A …

Nov 11, 2025
CVE-2025-20010
7.8 HIGH

Use of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of …

Nov 11, 2025
CVE-2025-12944
8.8 HIGH

Improper input validation in NETGEAR DGN2200v4 (N300 Wireless ADSL2+ Modem Router) allows attackers with direct network access to the device to potentially execute code on …

Nov 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.