CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 115488 CVEs

CVE ID Severity Description EPSS Published
8.8 HIGH

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

0.1% 2025-12-09
7.8 HIGH

Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
8.8 HIGH

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

0.1% 2025-12-09
8.4 HIGH

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.

0.2% 2025-12-09
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.

0.3% 2025-12-09
5.3 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

0.1% 2025-12-09
7.5 HIGH

Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

0.1% 2025-12-09
7.8 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
7.5 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
4.9 MEDIUM

A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to use the hash in place of the password to authenticate via crafted HTTP/HTTPS requests

0.1% 2025-12-09
8.1 HIGH

A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS request via forged cookies, requiring prior knowledge of the FortiWeb serial number.

0.2% 2025-12-09
7.2 HIGH

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7, FortiVoice 6.4 all versions, FortiVoice 6.0 all versions may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests

0.1% 2025-12-09
7.2 HIGH

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request.

0.2% 2025-12-09
7.5 HIGH

A NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.

0.1% 2025-12-09
7.5 HIGH

A NULL pointer dereference vulnerability in the importDataObject() function of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.

0.1% 2025-12-09
5.6 MEDIUM

An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSLVPN session not terminated after a user's password change under particular conditions outside of the attacker's control

0.0% 2025-12-09
7.0 HIGH

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
7.8 HIGH

Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
7.8 HIGH

Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.

0.2% 2025-12-09
7.1 HIGH

Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.

0.1% 2025-12-09
7.0 HIGH

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
5.3 MEDIUM

Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.

0.2% 2025-12-09
7.3 HIGH

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
7.8 HIGH

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

0.1% 2025-12-09
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

0.0% 2025-12-09
7.8 HIGH

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

0.1% 2025-12-09
7.8 HIGH

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

0.1% 2025-12-09
7.8 HIGH

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

0.1% 2025-12-09
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

0.2% 2025-12-09
7.8 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

0.2% 2025-12-09
8.4 HIGH

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

0.1% 2025-12-09
7.8 HIGH

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

0.1% 2025-12-09
7.0 HIGH

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

0.2% 2025-12-09
8.4 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

0.3% 2025-12-09
7.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

0.0% 2025-12-09
7.8 HIGH

Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.

0.1% 2025-12-09
8.8 HIGH

Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

0.2% 2025-12-09
8.8 HIGH

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

0.2% 2025-12-09
7.8 HIGH

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
6.5 MEDIUM

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

0.1% 2025-12-09
7.8 HIGH

Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

0.3% 2025-12-09
7.8 HIGH

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
5.5 MEDIUM

Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

0.1% 2025-12-09
7.8 HIGH

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
7.8 HIGH

Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
6.5 MEDIUM

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

0.1% 2025-12-09
7.8 HIGH

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09
6.5 MEDIUM

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

0.1% 2025-12-09
7.8 HIGH

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

0.1% 2025-12-09