Search and browse vulnerability records from NVD
Showing 50 of 24570 CVEs
| CVE ID | Severity | Description | EPSS | Published | |
|---|---|---|---|---|---|
| 7.8 HIGH |
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
0.2% | 2025-12-09 | ||
| 7.8 HIGH |
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
0.2% | 2025-12-09 | ||
| 8.4 HIGH |
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
0.1% | 2025-12-09 | ||
| 7.0 HIGH |
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
0.2% | 2025-12-09 | ||
| 8.4 HIGH |
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
0.3% | 2025-12-09 | ||
| 7.8 HIGH |
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
0.0% | 2025-12-09 | ||
| 7.8 HIGH |
Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally. |
0.1% | 2025-12-09 | ||
| 8.8 HIGH |
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. |
0.2% | 2025-12-09 | ||
| 8.8 HIGH |
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
0.2% | 2025-12-09 | ||
| 7.8 HIGH |
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
0.3% | 2025-12-09 | ||
| 7.8 HIGH |
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 7.0 HIGH |
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 8.8 HIGH |
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. |
0.2% | 2025-12-09 | ||
| 7.8 HIGH |
Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
|
CVE-2025-62221
KEV
|
7.8 HIGH |
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
3.2% | 2025-12-09 | |
| 7.5 HIGH |
Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the body length. NOTE: the Supplier indicates that they are unable to reproduce this. |
0.2% | 2025-12-09 | ||
| 8.8 HIGH |
Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged authenticated attacker to write arbitrary files via specifically HTTP or HTTPS commands |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. |
0.3% | 2025-12-09 | ||
| 7.8 HIGH |
Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally. |
0.1% | 2025-12-09 | ||
| 7.8 HIGH |
Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally. |
0.4% | 2025-12-09 | ||
| 7.2 HIGH |
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests. |
0.2% | 2025-12-09 | ||
| 7.2 HIGH |
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox Cloud 24.1, FortiSandbox Cloud 23 all versions allows a remote privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests. |
0.3% | 2025-12-09 | ||
| 7.3 HIGH |
Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local malicious user could potentially exploit this vulnerability, leading to Elevation of privileges. |
0.0% | 2025-12-09 | ||
| 7.3 HIGH |
MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAINFY.DLL from its application directo without sufficient integrity validation or secure search order. If the DLL is missing or attacker-writable locations in the search path are used, a local attacker with write permissions to the directory can plant a malicious MEAINFY.DLL. When the executable is launched, it loads the attacker-controlled library and executes code with the privileges of the process, enabling local privilege escalation when run with elevated rights. |
0.0% | 2025-12-09 | ||
| 8.8 HIGH |
NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering. |
0.1% | 2025-12-09 | ||
| 8.8 HIGH |
NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering. |
0.1% | 2025-12-09 | ||
| 8.8 HIGH |
LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An authenticated attacker can exploit this vulnerability by uploading a specially crafted ZIP/PHP file to execute arbitrary code. |
0.1% | 2025-12-09 | ||
| 7.5 HIGH |
A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46;β―RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36. |
0.1% | 2025-12-09 | ||
| 7.2 HIGH |
A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to improper input validation. This issue affects R7000P: through 1.3.3.154. |
0.7% | 2025-12-09 | ||
| 7.1 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in Jacques Malgrange Rencontre rencontre allows Stored XSS.This issue affects Rencontre: from n/a through <= 3.13.7. |
0.0% | 2025-12-09 | ||
| 7.1 HIGH |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Portfolio Post themify-portfolio-post allows Stored XSS.This issue affects Themify Portfolio Post: from n/a through <= 1.3.0. |
0.1% | 2025-12-09 | ||
| 7.5 HIGH |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Hara hara allows PHP Local File Inclusion.This issue affects Hara: from n/a through <= 1.2.17. |
0.2% | 2025-12-09 | ||
| 7.5 HIGH |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in trippleS Turitor turitor allows PHP Local File Inclusion.This issue affects Turitor: from n/a through < 1.5.3. |
0.2% | 2025-12-09 | ||
| 7.5 HIGH |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local File Inclusion.This issue affects Besa: from n/a through <= 2.3.15. |
0.2% | 2025-12-09 | ||
| 7.5 HIGH |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Opal_WP Fashion fashion2 allows PHP Local File Inclusion.This issue affects Fashion: from n/a through < 5.3.0. |
0.2% | 2025-12-09 | ||
| 7.5 HIGH |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP Local File Inclusion.This issue affects Urna: from n/a through <= 2.5.12. |
0.1% | 2025-12-09 | ||
| 7.5 HIGH |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in trippleS Digiqole digiqole allows PHP Local File Inclusion.This issue affects Digiqole: from n/a through < 2.2.7. |
0.2% | 2025-12-09 | ||
| 7.5 HIGH |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress Sailing sailing allows PHP Local File Inclusion.This issue affects Sailing: from n/a through < 4.4.6. |
0.2% | 2025-12-09 |