CVE Database

116905+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-43593
7.8 HIGH

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jun 10, 2025
CVE-2025-43590
7.8 HIGH

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jun 10, 2025
CVE-2025-43589
7.8 HIGH

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Jun 10, 2025
CVE-2025-43558
7.8 HIGH

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jun 10, 2025
CVE-2025-33112
8.4 HIGH

IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to …

Jun 10, 2025
CVE-2025-33075
7.8 HIGH

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-33073
8.8 HIGH KEV

Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

Jun 10, 2025
CVE-2025-33071
8.1 HIGH

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

Jun 10, 2025
CVE-2025-33070
8.1 HIGH

Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.

Jun 10, 2025
CVE-2025-33069
5.1 MEDIUM

Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.

Jun 10, 2025
CVE-2025-33068
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Jun 10, 2025
CVE-2025-33067
8.4 HIGH

Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-33066
8.8 HIGH

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Jun 10, 2025
CVE-2025-33065
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33064
8.8 HIGH

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Jun 10, 2025
CVE-2025-33063
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33062
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33061
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33060
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33059
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33058
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33057
6.5 MEDIUM

Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.

Jun 10, 2025
CVE-2025-33056
7.5 HIGH

Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.

Jun 10, 2025
CVE-2025-33055
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33053
8.8 HIGH KEV

External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

Jun 10, 2025
CVE-2025-33052
5.5 MEDIUM

Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-33050
7.5 HIGH

Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Jun 10, 2025
CVE-2025-32725
7.5 HIGH

Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Jun 10, 2025
CVE-2025-32724
7.5 HIGH

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Jun 10, 2025
CVE-2025-32722
5.5 MEDIUM

Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-32721
7.3 HIGH

Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-32720
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-32719
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-32718
7.8 HIGH

Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-32716
7.8 HIGH

Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-32715
6.5 MEDIUM

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Jun 10, 2025
CVE-2025-32714
7.8 HIGH

Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-32713
7.8 HIGH

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-32712
7.8 HIGH

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Jun 10, 2025
CVE-2025-32710
8.1 HIGH

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Jun 10, 2025
CVE-2025-31104
7.2 HIGH

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 …

Jun 10, 2025
CVE-2025-30321
5.5 MEDIUM

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit …

Jun 10, 2025
CVE-2025-30317
7.8 HIGH

InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jun 10, 2025
CVE-2025-29828
8.1 HIGH

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.

Jun 10, 2025
CVE-2025-25250
4.3 MEDIUM

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, …

Jun 10, 2025
CVE-2025-24471
6.5 MEDIUM

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect …

Jun 10, 2025
CVE-2025-24069
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-24068
5.5 MEDIUM

Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-24065
5.5 MEDIUM

Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

Jun 10, 2025
CVE-2025-22256
6.3 MEDIUM

A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through …

Jun 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.