Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
85,954 matching · page 382/1720Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2025-27166(opens NVD record) | High | 7.8 | InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-27164(opens NVD record) | Medium | 5.5 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-27163(opens NVD record) | Medium | 5.5 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-27162(opens NVD record) | High | 7.8 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-27161(opens NVD record) | High | 7.8 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-27160(opens NVD record) | High | 7.8 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-27159(opens NVD record) | High | 7.8 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-27158(opens NVD record) | High | 7.8 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-24453(opens NVD record) | High | 7.8 | InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-24452(opens NVD record) | High | 7.8 | InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-24449(opens NVD record) | Medium | 5.5 | Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-24448(opens NVD record) | Medium | 5.5 | Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-24431(opens NVD record) | Medium | 5.5 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Mar 11, 2025 |
| CVE-2025-26645(opens NVD record) | High | 8.8 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | Mar 11, 2025 |
| CVE-2025-26634(opens NVD record) | High | 7.5 | Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network. | Mar 11, 2025 |
| CVE-2025-26633(opens NVD record) | High | 7.0 | Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. | Mar 11, 2025 |
| CVE-2025-26631(opens NVD record) | High | 7.3 | Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-26630(opens NVD record) | High | 7.8 | Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-26629(opens NVD record) | High | 7.8 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-26627(opens NVD record) | High | 7.0 | Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-25008(opens NVD record) | High | 7.1 | Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-25003(opens NVD record) | High | 7.3 | Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24998(opens NVD record) | High | 7.3 | Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24997(opens NVD record) | Medium | 4.4 | Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally. | Mar 11, 2025 |
| CVE-2025-24996(opens NVD record) | Medium | 6.5 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | Mar 11, 2025 |
| CVE-2025-24995(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24994(opens NVD record) | High | 7.3 | Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24993(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-24992(opens NVD record) | Medium | 5.5 | Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally. | Mar 11, 2025 |
| CVE-2025-24991(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | Mar 11, 2025 |
| CVE-2025-24988(opens NVD record) | Medium | 6.6 | Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. | Mar 11, 2025 |
| CVE-2025-24987(opens NVD record) | Medium | 6.6 | Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. | Mar 11, 2025 |
| CVE-2025-24986(opens NVD record) | Medium | 6.5 | Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network. | Mar 11, 2025 |
| CVE-2025-24985(opens NVD record) | High | 7.8 | Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-24984(opens NVD record) | Medium | 4.6 | Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. | Mar 11, 2025 |
| CVE-2025-24983(opens NVD record) | High | 7.0 | Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24084(opens NVD record) | High | 8.4 | Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-24083(opens NVD record) | High | 7.8 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-24082(opens NVD record) | High | 7.8 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-24081(opens NVD record) | High | 7.8 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-24080(opens NVD record) | High | 7.8 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-24079(opens NVD record) | High | 7.8 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-24078(opens NVD record) | High | 7.0 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-24077(opens NVD record) | High | 7.8 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-24076(opens NVD record) | High | 7.3 | Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24075(opens NVD record) | High | 7.8 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | Mar 11, 2025 |
| CVE-2025-24072(opens NVD record) | High | 7.8 | Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |
| CVE-2025-24071(opens NVD record) | Medium | 6.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. | Mar 11, 2025 |
| CVE-2025-24070(opens NVD record) | High | 7.0 | Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. | Mar 11, 2025 |
| CVE-2025-24067(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. | Mar 11, 2025 |