Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
29,437 matching · page 464/589Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2025-54112(opens NVD record) | High | 7.0 | Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54111(opens NVD record) | High | 7.8 | Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54110(opens NVD record) | High | 8.8 | Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54109(opens NVD record) | Medium | 6.7 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54108(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54107(opens NVD record) | Medium | 4.3 | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | Sep 9, 2025 |
| CVE-2025-54106(opens NVD record) | High | 8.8 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | Sep 9, 2025 |
| CVE-2025-54105(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54104(opens NVD record) | Medium | 6.7 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54103(opens NVD record) | High | 7.4 | Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54102(opens NVD record) | High | 7.8 | Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54101(opens NVD record) | Medium | 4.8 | Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network. | Sep 9, 2025 |
| CVE-2025-54099(opens NVD record) | High | 7.0 | Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54098(opens NVD record) | High | 7.8 | Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54097(opens NVD record) | Medium | 6.5 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Sep 9, 2025 |
| CVE-2025-54096(opens NVD record) | Medium | 6.5 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Sep 9, 2025 |
| CVE-2025-54095(opens NVD record) | Medium | 6.5 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Sep 9, 2025 |
| CVE-2025-54094(opens NVD record) | Medium | 6.7 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54093(opens NVD record) | High | 7.0 | Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54092(opens NVD record) | High | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-54091(opens NVD record) | High | 7.8 | Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-53810(opens NVD record) | Medium | 6.7 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-53809(opens NVD record) | Medium | 6.5 | Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. | Sep 9, 2025 |
| CVE-2025-53808(opens NVD record) | Medium | 6.7 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-53807(opens NVD record) | High | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-53806(opens NVD record) | Medium | 6.5 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Sep 9, 2025 |
| CVE-2025-53805(opens NVD record) | High | 7.5 | Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network. | Sep 9, 2025 |
| CVE-2025-53804(opens NVD record) | Medium | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | Sep 9, 2025 |
| CVE-2025-53803(opens NVD record) | Medium | 5.5 | Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | Sep 9, 2025 |
| CVE-2025-53802(opens NVD record) | High | 7.0 | Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-53801(opens NVD record) | High | 7.8 | Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-53800(opens NVD record) | High | 7.8 | No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-53799(opens NVD record) | Medium | 5.5 | Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. | Sep 9, 2025 |
| CVE-2025-53798(opens NVD record) | Medium | 6.5 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Sep 9, 2025 |
| CVE-2025-53797(opens NVD record) | Medium | 6.5 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Sep 9, 2025 |
| CVE-2025-53796(opens NVD record) | Medium | 6.5 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | Sep 9, 2025 |
| CVE-2025-49734(opens NVD record) | High | 7.0 | Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-49692(opens NVD record) | High | 7.8 | Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | Sep 9, 2025 |
| CVE-2025-47997(opens NVD record) | Medium | 6.5 | Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. | Sep 9, 2025 |
| CVE-2025-9872(opens NVD record) | High | 8.8 | Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. | Sep 9, 2025 |
| CVE-2025-9712(opens NVD record) | High | 8.8 | Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. | Sep 9, 2025 |
| CVE-2025-8712(opens NVD record) | Medium | 5.4 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure restricted settings. | Sep 9, 2025 |
| CVE-2025-8711(opens NVD record) | Medium | 5.4 | CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to execute limited actions on behalf of the victim user. User interaction is required. | Sep 9, 2025 |
| CVE-2025-55148(opens NVD record) | High | 7.6 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure restricted settings. | Sep 9, 2025 |
| CVE-2025-55147(opens NVD record) | High | 8.8 | CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to execute sensitive actions on behalf of the victim user. User interaction is required | Sep 9, 2025 |
| CVE-2025-55146(opens NVD record) | Medium | 4.9 | An unchecked return value in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to trigger a denial of service. | Sep 9, 2025 |
| CVE-2025-55145(opens NVD record) | High | 8.9 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker to hijack existing HTML5 connections. | Sep 9, 2025 |
| CVE-2025-55144(opens NVD record) | Medium | 5.4 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure restricted settings. | Sep 9, 2025 |
| CVE-2025-55143(opens NVD record) | Medium | 6.1 | Reflected text injection in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to inject arbitrary text into a crafted HTTP response. User interaction is required. | Sep 9, 2025 |
| CVE-2025-55142(opens NVD record) | High | 8.8 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure authentication related settings. | Sep 9, 2025 |