Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 251–275 of 78,575 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-54109 | MEDIUM | Patched | 6.7 | 2025-09-09 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54110 | HIGH | Patched | 8.8 | 2025-09-09 | Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54111 | HIGH | Patched | 7.8 | 2025-09-09 | Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54112 | HIGH | Patched | 7.0 | 2025-09-09 | Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54113 | HIGH | Patched | 8.8 | 2025-09-09 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| CVE-2025-54114 | HIGH | Patched | 7.0 | 2025-09-09 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to e… |
| CVE-2025-54115 | HIGH | Patched | 7.0 | 2025-09-09 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54116 | HIGH | Patched | 7.3 | 2025-09-09 | Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54246 | MEDIUM | Patched | 6.5 | 2025-09-09 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privil… |
| CVE-2025-54247 | MEDIUM | Patched | 6.5 | 2025-09-09 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-priv… |
| CVE-2025-54248 | HIGH | Patched | 7.7 | 2025-09-09 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-priv… |
| CVE-2025-54249 | MEDIUM | Patched | 6.5 | 2025-09-09 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A … |
| CVE-2025-54250 | MEDIUM | Patched | 4.9 | 2025-09-09 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A high-pri… |
| CVE-2025-54251 | MEDIUM | Patched | 4.3 | 2025-09-09 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection vulnerability that could result in a Security feature bypass. A low-privileged attac… |
| CVE-2025-54252 | MEDIUM | Patched | 5.4 | 2025-09-09 | Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker t… |
| CVE-2025-54261 | CRITICAL | 10.0 | 2025-09-09 | ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability tha… | |
| CVE-2025-54709 | HIGH | 8.1 | 2025-09-09 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Sala. This issue affects Sala: from n/a throu… | |
| CVE-2025-54894 | HIGH | Patched | 7.8 | 2025-09-09 | Local Security Authority Subsystem Service Elevation of Privilege Vulnerability |
| CVE-2025-54895 | HIGH | Patched | 7.8 | 2025-09-09 | Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally. |
| CVE-2025-54896 | HIGH | Patched | 7.8 | 2025-09-09 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-54897 | HIGH | Patched | 8.8 | 2025-09-09 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-54898 | HIGH | Patched | 7.8 | 2025-09-09 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-54899 | HIGH | 7.8 | 2025-09-09 | Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| CVE-2025-54900 | HIGH | Patched | 7.8 | 2025-09-09 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| CVE-2025-54901 | MEDIUM | 5.5 | 2025-09-09 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |