CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-59508
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59507
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59506
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59505
7.8 HIGH

Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-59504
7.3 HIGH

Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

Nov 11, 2025
CVE-2025-59499
8.8 HIGH

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Nov 11, 2025
CVE-2025-59240
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Nov 11, 2025
CVE-2025-47179
6.7 MEDIUM

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.

Nov 11, 2025
CVE-2025-30398
8.1 HIGH

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

Nov 11, 2025
CVE-2025-61832
7.8 HIGH

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-61824
7.8 HIGH

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-61818
7.8 HIGH

InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Nov 11, 2025
CVE-2025-61817
7.8 HIGH

InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Nov 11, 2025
CVE-2025-61816
7.8 HIGH

InCopy versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Nov 11, 2025
CVE-2025-61815
7.8 HIGH

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-61814
7.8 HIGH

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Nov 11, 2025
CVE-2025-35972
6.7 MEDIUM

Uncontrolled search path for the Intel MPI Library before version 2021.16 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary …

Nov 11, 2025
CVE-2025-35971
8.2 HIGH

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged …

Nov 11, 2025
CVE-2025-35968
6.4 MEDIUM

Protection mechanism failure in the UEFI firmware for the Slim Bootloader within firmware may allow an escalation of privilege. Startup code and smm adversary with …

Nov 11, 2025
CVE-2025-35967
7.4 HIGH

Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged …

Nov 11, 2025
CVE-2025-35963
7.4 HIGH

Insufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of …

Nov 11, 2025
CVE-2025-33202
6.5 MEDIUM

NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where an attacker could cause a stack overflow by sending extra-large payloads. A successful …

Nov 11, 2025
CVE-2025-33186
8.8 HIGH

NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.

Nov 11, 2025
CVE-2025-33185
5.3 MEDIUM

NVIDIA AIStore contains a vulnerability in AuthN where an unauthenticated user may cause information disclosure. A successful exploit of this vulnerability may lead to information …

Nov 11, 2025
CVE-2025-33178
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data created by an attacker may cause a code …

Nov 11, 2025
CVE-2025-33029
7.4 HIGH

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged …

Nov 11, 2025
CVE-2025-33000
8.8 HIGH

Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary …

Nov 11, 2025
CVE-2025-32732
6.6 MEDIUM

Buffer overflow for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary …

Nov 11, 2025
CVE-2025-32449
6.7 MEDIUM

Unquoted search path for some PRI Driver software before version 03.03.1002 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary …

Nov 11, 2025
CVE-2025-32446
6.5 MEDIUM

Untrusted pointer dereference for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software …

Nov 11, 2025
CVE-2025-32091
8.2 HIGH

Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may allow an escalation of privilege. System software …

Nov 11, 2025
CVE-2025-32088
3.3 LOW

Improper conditions check for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software …

Nov 11, 2025
CVE-2025-32038
6.7 MEDIUM

Uncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 2025.0.1 within Ring 3: User Applications may allow …

Nov 11, 2025
CVE-2025-32037
2.0 LOW

Improper access control for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may allow a denial of service. Network adversary with a …

Nov 11, 2025
CVE-2025-32001
6.7 MEDIUM

Uncontrolled search path for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software …

Nov 11, 2025
CVE-2025-31948
3.3 LOW

Improper input validation for some Intel(R) oneAPI Math Kernel Library before version 2025.2 within Ring 3: User Applications may allow a denial of service. Unprivileged …

Nov 11, 2025
CVE-2025-31940
6.7 MEDIUM

Incorrect default permissions for some Intel(R) Thread Director Visualizer software before version 1.1.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged …

Nov 11, 2025
CVE-2025-31937
5.6 MEDIUM

Out-of-bounds read for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of service. System software adversary …

Nov 11, 2025
CVE-2025-31931
6.7 MEDIUM

Uncontrolled search path for the Instrumentation and Tracing Technology API (ITT API) software before version 3.25.4 within Ring 3: User Applications may allow an escalation …

Nov 11, 2025
CVE-2025-31647
6.7 MEDIUM

Uncontrolled search path for some Intel(R) Graphics Software before version 25.22.1502.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary …

Nov 11, 2025
CVE-2025-31645
6.7 MEDIUM

Uncontrolled search path for some System Event Log Viewer Utility software for all versions within Ring 3: User Applications may allow an escalation of privilege. …

Nov 11, 2025
CVE-2025-31146
6.1 MEDIUM

Time-of-check time-of-use race condition for some Intel Ethernet Adapter Complete Driver Pack software before version 1.5.1.0 within Ring 3: User Applications may allow a denial …

Nov 11, 2025
CVE-2025-30518
6.7 MEDIUM

Incorrect default permissions for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with …

Nov 11, 2025
CVE-2025-30509
3.8 LOW

Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applications may allow an escalation of privilege. System software …

Nov 11, 2025
CVE-2025-30506
6.7 MEDIUM

Uncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged …

Nov 11, 2025
CVE-2025-30255
8.2 HIGH

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged …

Nov 11, 2025
CVE-2025-30185
7.9 HIGH

Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escalation of privilege. System software …

Nov 11, 2025
CVE-2025-30182
6.7 MEDIUM

Uncontrolled search path for some Intel(R) Distribution for Python software installers before version 2025.2.0 within Ring 3: User Applications may allow an escalation of privilege. …

Nov 11, 2025
CVE-2025-27725
4.4 MEDIUM

Time-of-check time-of-use race condition for some ACAT before version 3.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with …

Nov 11, 2025
CVE-2025-27713
7.8 HIGH

Out-of-bounds write for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary …

Nov 11, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.