CVE Database

117275+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47795
6.7 MEDIUM

Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.0 may allow an authenticated user to potentially enable escalation of privilege via …

May 13, 2025
CVE-2024-47550
6.7 MEDIUM

Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

May 13, 2025
CVE-2024-46895
6.7 MEDIUM

Uncontrolled search path for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101.5736 may allow an authenticated user to potentially enable escalation of …

May 13, 2025
CVE-2024-45371
6.7 MEDIUM

Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6077 may allow an authenticated user to potentially enable denial of …

May 13, 2025
CVE-2024-45333
7.3 HIGH

Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authenticated user to potentially enable …

May 13, 2025
CVE-2024-45332
5.6 MEDIUM

Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow …

May 13, 2025
CVE-2024-43420
5.6 MEDIUM

Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom(R) processors may allow an authenticated user to …

May 13, 2025
CVE-2024-43101
5.3 MEDIUM

Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver software before version 31.0.101.4255 may allow an authenticated user to potentially …

May 13, 2025
CVE-2024-39833
6.7 MEDIUM

Uncontrolled search path for some Intel(R) QAT software before version 2.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

May 13, 2025
CVE-2024-39758
5.9 MEDIUM

Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 31.0.101.4032 may allow an authenticated user to potentially enable denial of …

May 13, 2025
CVE-2024-36292
7.3 HIGH

Improper buffer restrictions for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 may allow an authenticated user to potentially enable …

May 13, 2025
CVE-2024-31150
3.8 LOW

Out-of-bounds read for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable information disclosure via local access.

May 13, 2025
CVE-2024-31073
6.7 MEDIUM

Uncontrolled search path for some Intel(R) oneAPI Level Zero software may allow an authenticated user to potentially enable escalation of privilege via local access.

May 13, 2025
CVE-2024-29222
6.1 MEDIUM

Out-of-bounds write for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable denial of service via local access.

May 13, 2025
CVE-2024-28956
5.6 MEDIUM

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure …

May 13, 2025
CVE-2024-28954
6.7 MEDIUM

Incorrect default permissions for some Intel(R) Graphics Driver installers may allow an authenticated user to potentially enable escalation of privilege via local access.

May 13, 2025
CVE-2024-28036
5.6 MEDIUM

Improper conditions check for some Intel(R) Arc™ GPU may allow an authenticated user to potentially enable denial of service via local access.

May 13, 2025
CVE-2025-45863
9.8 CRITICAL

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface.

May 13, 2025
CVE-2025-45865
9.8 CRITICAL

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.

May 13, 2025
CVE-2025-45861
9.8 CRITICAL

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.

May 13, 2025
CVE-2025-45746
6.5 MEDIUM

In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier …

May 13, 2025
CVE-2025-3744
7.6 HIGH

Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise …

May 13, 2025
CVE-2025-4660
9.8 CRITICAL

A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is …

May 13, 2025
CVE-2025-43557
7.8 HIGH

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-43556
7.8 HIGH

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-43555
7.8 HIGH

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

May 13, 2025
CVE-2025-43547
7.8 HIGH

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-43546
7.8 HIGH

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

May 13, 2025
CVE-2025-43545
7.8 HIGH

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context …

May 13, 2025
CVE-2025-30330
7.8 HIGH

Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

May 13, 2025
CVE-2025-30329
5.5 MEDIUM

Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this …

May 13, 2025
CVE-2025-30328
7.8 HIGH

Animate versions 24.0.8, 23.0.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

May 13, 2025
CVE-2025-30326
7.8 HIGH

Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the …

May 13, 2025
CVE-2025-30325
7.8 HIGH

Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the …

May 13, 2025
CVE-2025-30324
7.8 HIGH

Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

May 13, 2025
CVE-2025-30322
7.8 HIGH

Substance3D - Painter versions 11.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 13, 2025
CVE-2025-27197
7.8 HIGH

Lightroom Desktop versions 8.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

May 13, 2025
CVE-2023-31359
7.3 HIGH

Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

May 13, 2025
CVE-2023-31358
7.3 HIGH

A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

May 13, 2025
CVE-2025-4658
9.8 CRITICAL

Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification. As OPKSSH depends on …

May 13, 2025
CVE-2025-47280
6.1 MEDIUM

Umbraco Forms is a form builder that integrates with the Umbraco content management system. Starting in the 7.x branch and prior to versions 13.4.2 and …

May 13, 2025
CVE-2025-3757
9.8 CRITICAL

Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to bypass signature verification.

May 13, 2025
CVE-2025-32709
7.8 HIGH KEV

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

May 13, 2025
CVE-2025-32707
7.8 HIGH

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

May 13, 2025
CVE-2025-32706
7.8 HIGH KEV

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

May 13, 2025
CVE-2025-32705
7.8 HIGH

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

May 13, 2025
CVE-2025-32704
8.4 HIGH

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

May 13, 2025
CVE-2025-32703
5.5 MEDIUM

Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.

May 13, 2025
CVE-2025-32702
7.8 HIGH

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.

May 13, 2025
CVE-2025-32701
7.8 HIGH KEV

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

May 13, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.