CVE Database

39635+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-26627
7.0 HIGH

Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-25008
7.1 HIGH

Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-25003
7.3 HIGH

Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24998
7.3 HIGH

Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24995
7.8 HIGH

Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24994
7.3 HIGH

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24993
7.8 HIGH KEV

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24985
7.8 HIGH KEV

Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24983
7.0 HIGH KEV

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24084
8.4 HIGH

Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24083
7.8 HIGH

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24082
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24081
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24080
7.8 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24079
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24078
7.0 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24077
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24076
7.3 HIGH

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24075
7.8 HIGH

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24072
7.8 HIGH

Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24070
7.0 HIGH

Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

Mar 11, 2025
CVE-2025-24067
7.8 HIGH

Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24066
7.8 HIGH

Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24064
8.1 HIGH

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-24061
7.8 HIGH

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.

Mar 11, 2025
CVE-2025-24059
7.8 HIGH

Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24057
7.8 HIGH

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-24056
8.8 HIGH

Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-24051
8.8 HIGH

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-24050
7.8 HIGH

Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24049
8.4 HIGH

Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24048
7.8 HIGH

Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24046
7.8 HIGH

Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24045
8.1 HIGH

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-24044
7.8 HIGH

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

Mar 11, 2025
CVE-2025-24043
7.5 HIGH

Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-24035
8.1 HIGH

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Mar 11, 2025
CVE-2025-21180
7.8 HIGH

Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.

Mar 11, 2025
CVE-2025-21169
7.8 HIGH

Substance3D - Designer versions 14.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Mar 11, 2025
CVE-2024-9157
7.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a …

Mar 11, 2025
CVE-2025-27617
8.8 HIGH

Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a …

Mar 11, 2025
CVE-2025-25680
7.7 HIGH

LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary …

Mar 11, 2025
CVE-2025-22454
7.8 HIGH

Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

Mar 11, 2025
CVE-2024-55590
8.8 HIGH

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an …

Mar 11, 2025
CVE-2024-54018
7.2 HIGH

Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands …

Mar 11, 2025
CVE-2024-52961
8.8 HIGH

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through …

Mar 11, 2025
CVE-2024-51321
7.6 HIGH

In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled website after …

Mar 11, 2025
CVE-2024-51319
7.3 HIGH

A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading …

Mar 11, 2025
CVE-2024-45328
7.8 HIGH

An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated CLI commands via the GUI console …

Mar 11, 2025
CVE-2024-45324
7.2 HIGH

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, …

Mar 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.