CVE Database

113799+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64156
7.2 HIGH

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7, FortiVoice …

Dec 9, 2025
CVE-2025-64153
7.2 HIGH

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender …

Dec 9, 2025
CVE-2025-64086
7.5 HIGH

A NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted …

Dec 9, 2025
CVE-2025-64085
7.5 HIGH

A NULL pointer dereference vulnerability in the importDataObject() function of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted …

Dec 9, 2025
CVE-2025-62631
5.6 MEDIUM

An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker …

Dec 9, 2025
CVE-2025-62573
7.0 HIGH

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62572
7.8 HIGH

Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62571
7.8 HIGH

Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62570
7.1 HIGH

Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.

Dec 9, 2025
CVE-2025-62569
7.0 HIGH

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62567
5.3 MEDIUM

Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.

Dec 9, 2025
CVE-2025-62565
7.3 HIGH

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62564
7.8 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62563
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62562
7.8 HIGH

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62561
7.8 HIGH

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62560
7.8 HIGH

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62559
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62558
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62557
8.4 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62556
7.8 HIGH

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62555
7.0 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62554
8.4 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62553
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62552
7.8 HIGH

Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Dec 9, 2025
CVE-2025-62550
8.8 HIGH

Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

Dec 9, 2025
CVE-2025-62549
8.8 HIGH

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Dec 9, 2025
CVE-2025-62474
7.8 HIGH

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62473
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Dec 9, 2025
CVE-2025-62472
7.8 HIGH

Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62470
7.8 HIGH

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62469
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62468
5.5 MEDIUM

Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

Dec 9, 2025
CVE-2025-62467
7.8 HIGH

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62466
7.8 HIGH

Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62465
6.5 MEDIUM

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

Dec 9, 2025
CVE-2025-62464
7.8 HIGH

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62463
6.5 MEDIUM

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

Dec 9, 2025
CVE-2025-62462
7.8 HIGH

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62461
7.8 HIGH

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62458
7.8 HIGH

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62457
7.8 HIGH

Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62456
8.8 HIGH

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.

Dec 9, 2025
CVE-2025-62455
7.8 HIGH

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62454
7.8 HIGH

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-62221
7.8 HIGH KEV

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Dec 9, 2025
CVE-2025-61258
7.5 HIGH

Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the body length. NOTE: the Supplier indicates …

Dec 9, 2025
CVE-2025-61078
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter …

Dec 9, 2025
CVE-2025-60024
8.8 HIGH

Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 …

Dec 9, 2025
CVE-2025-59923
2.7 LOW

An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow …

Dec 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.