CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-27200
7.8 HIGH

Animate versions 24.0.7, 23.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27199
7.8 HIGH

Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27198
7.8 HIGH

Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-27196
7.8 HIGH

Premiere Pro versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-27195
7.8 HIGH

Media Encoder versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Apr 8, 2025
CVE-2025-27194
7.8 HIGH

Media Encoder versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27193
7.8 HIGH

Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27187
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-27186
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-27185
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Apr 8, 2025
CVE-2025-27184
5.5 MEDIUM

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Apr 8, 2025
CVE-2025-27183
7.8 HIGH

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-27182
7.8 HIGH

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Apr 8, 2025
CVE-2025-26688
7.8 HIGH

Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26687
7.5 HIGH

Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.

Apr 8, 2025
CVE-2025-26686
7.5 HIGH

Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26682
7.5 HIGH

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26681
6.7 MEDIUM

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26680
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26679
7.8 HIGH

Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26678
8.4 HIGH

Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.

Apr 8, 2025
CVE-2025-26676
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-26675
7.8 HIGH

Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26674
7.8 HIGH

Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-26673
7.5 HIGH

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26672
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-26671
8.1 HIGH

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26670
8.1 HIGH

Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26669
8.8 HIGH

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-26668
7.5 HIGH

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26667
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a …

Apr 8, 2025
CVE-2025-26666
7.8 HIGH

Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-26665
7.0 HIGH

Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26664
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Apr 8, 2025
CVE-2025-26663
8.1 HIGH

Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

Apr 8, 2025
CVE-2025-26652
7.5 HIGH

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26651
6.5 MEDIUM

Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26649
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26648
7.8 HIGH

Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26647
8.8 HIGH

Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

Apr 8, 2025
CVE-2025-26644
5.1 MEDIUM

Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.

Apr 8, 2025
CVE-2025-26642
7.8 HIGH

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

Apr 8, 2025
CVE-2025-26641
7.5 HIGH

Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

Apr 8, 2025
CVE-2025-26640
7.0 HIGH

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26639
7.8 HIGH

Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

Apr 8, 2025
CVE-2025-26637
6.8 MEDIUM

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Apr 8, 2025
CVE-2025-26635
6.5 MEDIUM

Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.

Apr 8, 2025
CVE-2025-26628
7.3 HIGH

Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.

Apr 8, 2025
CVE-2025-25002
6.8 MEDIUM

Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.

Apr 8, 2025
CVE-2025-24074
7.8 HIGH

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Apr 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.