CVE Database

39635+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27731
7.8 HIGH

Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27730
7.8 HIGH

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27729
7.8 HIGH

Use after free in Windows Shell allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-27728
7.8 HIGH

Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27727
7.8 HIGH

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27492
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27491
7.1 HIGH

Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-27490
7.8 HIGH

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27489
7.8 HIGH

Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27487
8.0 HIGH

Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-27486
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-27485
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-27484
7.5 HIGH

Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a …

Apr 8, 2025
CVE-2025-27483
7.8 HIGH

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27482
8.1 HIGH

Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-27481
8.8 HIGH

Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-27480
8.1 HIGH

Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-27479
7.5 HIGH

Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-27478
7.0 HIGH

Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27477
8.8 HIGH

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-27476
7.8 HIGH

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27475
7.0 HIGH

Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27473
7.5 HIGH

Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-27470
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-27469
7.5 HIGH

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-27467
7.8 HIGH

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27200
7.8 HIGH

Animate versions 24.0.7, 23.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27199
7.8 HIGH

Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27198
7.8 HIGH

Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-27196
7.8 HIGH

Premiere Pro versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-27195
7.8 HIGH

Media Encoder versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-27194
7.8 HIGH

Media Encoder versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27193
7.8 HIGH

Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27183
7.8 HIGH

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27182
7.8 HIGH

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-26688
7.8 HIGH

Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26687
7.5 HIGH

Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.

Apr 8, 2025
CVE-2025-26686
7.5 HIGH

Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26682
7.5 HIGH

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26680
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26679
7.8 HIGH

Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26678
8.4 HIGH

Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.

Apr 8, 2025
CVE-2025-26675
7.8 HIGH

Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26674
7.8 HIGH

Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-26673
7.5 HIGH

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26671
8.1 HIGH

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26670
8.1 HIGH

Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26669
8.8 HIGH

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-26668
7.5 HIGH

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26666
7.8 HIGH

Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

Apr 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.