Latest CVE Feed
-
7.1
HIGHCVE-2025-0150
Incorrect behavior order in some Zoom Workplace Apps for iOS before version 6.3.0 may allow an authenticated user to conduct a denial of service via network access.... Read more
- Published: Mar. 11, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2021-37787
The unprivileged administrative interface in ABO.CMS version 5.8 through v.5.9.3 is affected by a SQL Injection vulnerability via a HTTP POST request to the TinyMCE module... Read more
Affected Products : abo.cms- Published: Mar. 11, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-27172
Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim m... Read more
Affected Products : substance_3d_designer- Published: Mar. 11, 2025
- Modified: Apr. 28, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-26645
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +14 more products- Published: Mar. 11, 2025
- Modified: Jul. 07, 2025
-
7.5
HIGHCVE-2025-26634
Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows +5 more products- Published: Mar. 11, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Memory Corruption
-
7.0
HIGHCVE-2025-26633
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Actively Exploited
- Published: Mar. 11, 2025
- Modified: Apr. 17, 2025
-
7.3
HIGHCVE-2025-26631
Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : visual_studio_code- Published: Mar. 11, 2025
- Modified: Jul. 03, 2025
-
7.8
HIGHCVE-2025-26630
Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.... Read more
Affected Products : office access 365_apps office_long_term_servicing_channel access_2016 office_2024 office_2021 office_2019- Published: Mar. 11, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-26629
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 01, 2025
-
7.0
HIGHCVE-2025-26627
Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : azure_arc- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-25008
Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 01, 2025
-
7.3
HIGHCVE-2025-25003
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 01, 2025
-
7.3
HIGHCVE-2025-24998
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authorization
-
4.4
MEDIUMCVE-2025-24997
Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2025-24996
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +9 more products- Published: Mar. 11, 2025
- Modified: Jul. 03, 2025
-
7.8
HIGHCVE-2025-24995
Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.... Read more
Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows +5 more products- Published: Mar. 11, 2025
- Modified: Jul. 03, 2025
-
7.3
HIGHCVE-2025-24994
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2025-24993
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Actively Exploited
- Published: Mar. 11, 2025
- Modified: Mar. 13, 2025
-
5.5
MEDIUMCVE-2025-24992
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Published: Mar. 11, 2025
- Modified: Jul. 03, 2025
-
5.5
MEDIUMCVE-2025-24991
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Actively Exploited
- Published: Mar. 11, 2025
- Modified: Mar. 13, 2025