Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
33,830 matching · page 576/677Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2025-0135(opens NVD record) | Low | 3.3 | An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected. | May 14, 2025 |
| CVE-2025-0130(opens NVD record) | High | 7.5 | A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode. This issue does not affect Cloud NGFW or Prisma Access. | May 14, 2025 |
| CVE-2025-3600(opens NVD record) | High | 7.5 | In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service. | May 14, 2025 |
| CVE-2024-57273(opens NVD record) | Medium | 5.4 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and a derivable device key generated from the public SSH key. | May 14, 2025 |
| CVE-2025-3834(opens NVD record) | High | 8.1 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report. | May 14, 2025 |
| CVE-2025-3833(opens NVD record) | High | 8.1 | Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports. | May 14, 2025 |
| CVE-2025-26646(opens NVD record) | High | 8.0 | External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. | May 13, 2025 |
| CVE-2025-43572(opens NVD record) | High | 7.8 | Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43571(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43570(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43569(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43568(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43551(opens NVD record) | Medium | 5.5 | Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43549(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43548(opens NVD record) | High | 7.8 | Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2024-28956(opens NVD record) | Medium | 5.6 | Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | May 13, 2025 |
| CVE-2025-4660(opens NVD record) | Critical | 9.8 | A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent. This does not impact Linux or OSX Secure Connector. | May 13, 2025 |
| CVE-2025-43557(opens NVD record) | High | 7.8 | Animate versions 24.0.8, 23.0.11 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43556(opens NVD record) | High | 7.8 | Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43555(opens NVD record) | High | 7.8 | Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43547(opens NVD record) | High | 7.8 | Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43546(opens NVD record) | High | 7.8 | Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43545(opens NVD record) | High | 7.8 | Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-30330(opens NVD record) | High | 7.8 | Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-30329(opens NVD record) | Medium | 5.5 | Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-30328(opens NVD record) | High | 7.8 | Animate versions 24.0.8, 23.0.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-30325(opens NVD record) | High | 7.8 | Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-30324(opens NVD record) | High | 7.8 | Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-32709(opens NVD record) | High | 7.8 | Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | May 13, 2025 |
| CVE-2025-32707(opens NVD record) | High | 7.8 | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | May 13, 2025 |
| CVE-2025-32706(opens NVD record) | High | 7.8 | Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | May 13, 2025 |
| CVE-2025-32705(opens NVD record) | High | 7.8 | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-32704(opens NVD record) | High | 8.4 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-32703(opens NVD record) | Medium | 5.5 | Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. | May 13, 2025 |
| CVE-2025-32702(opens NVD record) | High | 7.8 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-32701(opens NVD record) | High | 7.8 | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | May 13, 2025 |
| CVE-2025-30400(opens NVD record) | High | 7.8 | Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | May 13, 2025 |
| CVE-2025-30397(opens NVD record) | High | 7.5 | Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | May 13, 2025 |
| CVE-2025-30394(opens NVD record) | Medium | 5.9 | Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network. | May 13, 2025 |
| CVE-2025-30393(opens NVD record) | High | 7.8 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-30388(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-30387(opens NVD record) | Critical | 9.8 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network. | May 13, 2025 |
| CVE-2025-30386(opens NVD record) | High | 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-30385(opens NVD record) | High | 7.8 | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | May 13, 2025 |
| CVE-2025-30384(opens NVD record) | High | 7.4 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-30383(opens NVD record) | High | 7.8 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-30382(opens NVD record) | High | 7.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-30381(opens NVD record) | High | 7.8 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-30379(opens NVD record) | High | 7.8 | Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-30378(opens NVD record) | High | 7.0 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | May 13, 2025 |