CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 139587 CVEs

CVE ID Severity Description EPSS Published
5.5 MEDIUM

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

0.1% 2025-09-09
7.8 HIGH

Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
7.8 HIGH

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

0.1% 2025-09-09
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Sala. This issue affects Sala: from n/a through 1.1.6.

0.1% 2025-09-09
10.0 CRITICAL

ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim must have optional configurations enabled. Scope is changed.

3.0% 2025-09-09
4.3 MEDIUM

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to manipulate XML queries and gain limited unauthorized write access.

10.6% 2025-09-09
7.3 HIGH

Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
8.8 HIGH

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

0.1% 2025-09-09
7.0 HIGH

Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
7.8 HIGH

Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
8.8 HIGH

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

0.2% 2025-09-09
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
4.3 MEDIUM

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

0.1% 2025-09-09
8.8 HIGH

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

0.1% 2025-09-09
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

0.2% 2025-09-09
7.4 HIGH

Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally.

0.1% 2025-09-09
7.8 HIGH

Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
4.8 MEDIUM

Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.

0.2% 2025-09-09
7.0 HIGH

Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
7.8 HIGH

Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

0.1% 2025-09-09
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

0.1% 2025-09-09
6.5 MEDIUM

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

0.1% 2025-09-09
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

0.2% 2025-09-09
7.0 HIGH

Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
7.8 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
7.8 HIGH

Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

0.2% 2025-09-09
6.7 MEDIUM

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

0.2% 2025-09-09
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

0.1% 2025-09-09
7.5 HIGH

Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.

0.2% 2025-09-09
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

0.1% 2025-09-09
5.5 MEDIUM

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

0.1% 2025-09-09
7.0 HIGH

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
7.8 HIGH

Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.

0.1% 2025-09-09
7.8 HIGH

No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

0.2% 2025-09-09
5.5 MEDIUM

Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

0.1% 2025-09-09
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

0.1% 2025-09-09
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

0.1% 2025-09-09
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

0.1% 2025-09-09
5.3 MEDIUM

Missing Authorization vulnerability in Laborator Kalium kalium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kalium: from n/a through <= 3.18.3.

0.0% 2025-09-09
5.3 MEDIUM

Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a through <= 6.3.6.

0.0% 2025-09-09
8.8 HIGH

Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object Injection.This issue affects ThemeMove Core: from n/a through <= 1.4.2.

0.1% 2025-09-09
5.4 MEDIUM

Missing Authorization vulnerability in spoddev2021 Spreadconnect wc-spod.This issue affects Spreadconnect: from n/a through <= 2.1.5.

0.1% 2025-09-09
5.3 MEDIUM

Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Support: from n/a through <= 1.1.0.

0.0% 2025-09-09