Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
35,792 matching · page 631/716Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2025-26676(opens NVD record) | Medium | 6.5 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Apr 8, 2025 |
| CVE-2025-26675(opens NVD record) | High | 7.8 | Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-26674(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | Apr 8, 2025 |
| CVE-2025-26673(opens NVD record) | High | 7.5 | Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | Apr 8, 2025 |
| CVE-2025-26672(opens NVD record) | Medium | 6.5 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Apr 8, 2025 |
| CVE-2025-26671(opens NVD record) | High | 8.1 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | Apr 8, 2025 |
| CVE-2025-26670(opens NVD record) | High | 8.1 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | Apr 8, 2025 |
| CVE-2025-26669(opens NVD record) | High | 8.8 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Apr 8, 2025 |
| CVE-2025-26668(opens NVD record) | High | 7.5 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | Apr 8, 2025 |
| CVE-2025-26667(opens NVD record) | Medium | 6.5 | Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Apr 8, 2025 |
| CVE-2025-26666(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | Apr 8, 2025 |
| CVE-2025-26665(opens NVD record) | High | 7.0 | Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-26664(opens NVD record) | Medium | 6.5 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Apr 8, 2025 |
| CVE-2025-26663(opens NVD record) | High | 8.1 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | Apr 8, 2025 |
| CVE-2025-26652(opens NVD record) | High | 7.5 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | Apr 8, 2025 |
| CVE-2025-26651(opens NVD record) | Medium | 6.5 | Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. | Apr 8, 2025 |
| CVE-2025-26649(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-26648(opens NVD record) | High | 7.8 | Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-26647(opens NVD record) | High | 8.8 | Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | Apr 8, 2025 |
| CVE-2025-26644(opens NVD record) | Medium | 5.1 | Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally. | Apr 8, 2025 |
| CVE-2025-26642(opens NVD record) | High | 7.8 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | Apr 8, 2025 |
| CVE-2025-26641(opens NVD record) | High | 7.5 | Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. | Apr 8, 2025 |
| CVE-2025-26640(opens NVD record) | High | 7.0 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-26639(opens NVD record) | High | 7.8 | Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-26637(opens NVD record) | Medium | 6.8 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | Apr 8, 2025 |
| CVE-2025-26635(opens NVD record) | Medium | 6.5 | Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network. | Apr 8, 2025 |
| CVE-2025-26628(opens NVD record) | High | 7.3 | Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. | Apr 8, 2025 |
| CVE-2025-25002(opens NVD record) | Medium | 6.8 | Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. | Apr 8, 2025 |
| CVE-2025-24074(opens NVD record) | High | 7.8 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-24073(opens NVD record) | High | 7.8 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-24062(opens NVD record) | High | 7.8 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-24060(opens NVD record) | High | 7.8 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-24058(opens NVD record) | High | 7.8 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-21222(opens NVD record) | High | 8.8 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | Apr 8, 2025 |
| CVE-2025-21221(opens NVD record) | High | 8.8 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | Apr 8, 2025 |
| CVE-2025-21205(opens NVD record) | High | 8.8 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | Apr 8, 2025 |
| CVE-2025-21204(opens NVD record) | High | 7.8 | Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-21203(opens NVD record) | Medium | 6.5 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Apr 8, 2025 |
| CVE-2025-21197(opens NVD record) | Medium | 6.5 | Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content. | Apr 8, 2025 |
| CVE-2025-21191(opens NVD record) | High | 7.0 | Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. | Apr 8, 2025 |
| CVE-2025-21174(opens NVD record) | High | 7.5 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | Apr 8, 2025 |
| CVE-2025-27085(opens NVD record) | Medium | 4.9 | Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. | Apr 8, 2025 |
| CVE-2025-27084(opens NVD record) | Medium | 5.4 | A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the affected interface. | Apr 8, 2025 |
| CVE-2025-27083(opens NVD record) | High | 7.2 | Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on the underlying operating system. | Apr 8, 2025 |
| CVE-2025-27082(opens NVD record) | High | 7.2 | Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system. | Apr 8, 2025 |
| CVE-2024-48887(opens NVD record) | Critical | 9.8 | A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request | Apr 8, 2025 |
| CVE-2025-1095(opens NVD record) | High | 8.8 | IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the context of NT AUTHORITY\SYSTEM. This allows for a low privileged attacker to escalate their privileges. This vulnerability is due to an incomplete fix for CVE-2024-25029. | Apr 8, 2025 |
| CVE-2025-22466(opens NVD record) | High | 8.2 | Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required. | Apr 8, 2025 |
| CVE-2025-22465(opens NVD record) | Medium | 6.1 | Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in a victim's browser. Unlikely user interaction is required. | Apr 8, 2025 |
| CVE-2025-22464(opens NVD record) | Medium | 6.1 | An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition. | Apr 8, 2025 |