CVE Database

46519+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27480
8.1 HIGH

Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-27479
7.5 HIGH

Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-27478
7.0 HIGH

Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27477
8.8 HIGH

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-27476
7.8 HIGH

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27475
7.0 HIGH

Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27473
7.5 HIGH

Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-27470
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-27469
7.5 HIGH

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-27467
7.8 HIGH

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-27200
7.8 HIGH

Animate versions 24.0.7, 23.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27199
7.8 HIGH

Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27198
7.8 HIGH

Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-27196
7.8 HIGH

Premiere Pro versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-27195
7.8 HIGH

Media Encoder versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-27194
7.8 HIGH

Media Encoder versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27193
7.8 HIGH

Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27183
7.8 HIGH

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27182
7.8 HIGH

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-26688
7.8 HIGH

Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26687
7.5 HIGH

Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.

Apr 8, 2025
CVE-2025-26686
7.5 HIGH

Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26682
7.5 HIGH

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26680
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26679
7.8 HIGH

Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26678
8.4 HIGH

Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.

Apr 8, 2025
CVE-2025-26675
7.8 HIGH

Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26674
7.8 HIGH

Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-26673
7.5 HIGH

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26671
8.1 HIGH

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26670
8.1 HIGH

Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26669
8.8 HIGH

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-26668
7.5 HIGH

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26666
7.8 HIGH

Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-26665
7.0 HIGH

Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26663
8.1 HIGH

Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26652
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26649
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26648
7.8 HIGH

Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26647
8.8 HIGH

Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

Apr 8, 2025
CVE-2025-26642
7.8 HIGH

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-26641
7.5 HIGH

Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26640
7.0 HIGH

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26639
7.8 HIGH

Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26628
7.3 HIGH

Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.

Apr 8, 2025
CVE-2025-24074
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-24073
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-24062
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-24060
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-24058
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.