CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-59255
7.8 HIGH

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59254
7.8 HIGH

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59253
5.5 MEDIUM

Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

Oct 14, 2025
CVE-2025-59250
8.1 HIGH

Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.

Oct 14, 2025
CVE-2025-59249
8.8 HIGH

Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Oct 14, 2025
CVE-2025-59248
7.5 HIGH

Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Oct 14, 2025
CVE-2025-59244
6.5 MEDIUM

External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.

Oct 14, 2025
CVE-2025-59243
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59242
7.8 HIGH

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59241
7.8 HIGH

Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59238
7.8 HIGH

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59237
8.8 HIGH

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Oct 14, 2025
CVE-2025-59236
8.4 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59235
7.1 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59234
7.8 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59233
7.8 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59232
7.1 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59231
7.8 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59230
7.8 HIGH KEV

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59229
5.5 MEDIUM

Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.

Oct 14, 2025
CVE-2025-59228
8.8 HIGH

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Oct 14, 2025
CVE-2025-59227
7.8 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59226
7.8 HIGH

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59225
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59224
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59223
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59222
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59221
7.0 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Oct 14, 2025
CVE-2025-59214
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

Oct 14, 2025
CVE-2025-59213
8.8 HIGH

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an …

Oct 14, 2025
CVE-2025-59211
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59210
7.4 HIGH

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

Oct 14, 2025
CVE-2025-59209
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59208
7.1 HIGH

Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.

Oct 14, 2025
CVE-2025-59207
7.8 HIGH

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59206
7.4 HIGH

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

Oct 14, 2025
CVE-2025-59205
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59204
5.5 MEDIUM

Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59203
5.5 MEDIUM

Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59202
7.0 HIGH

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59201
7.8 HIGH

Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59200
7.7 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally.

Oct 14, 2025
CVE-2025-59199
7.8 HIGH

Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59198
5.0 MEDIUM

Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

Oct 14, 2025
CVE-2025-59197
5.5 MEDIUM

Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.

Oct 14, 2025
CVE-2025-59196
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59195
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.

Oct 14, 2025
CVE-2025-59194
7.0 HIGH

Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59193
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

Oct 14, 2025
CVE-2025-59192
7.8 HIGH

Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.

Oct 14, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.