Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
31,739 matching · page 528/635Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2025-33069(opens NVD record) | Medium | 5.1 | Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally. | Jun 10, 2025 |
| CVE-2025-33068(opens NVD record) | High | 7.5 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | Jun 10, 2025 |
| CVE-2025-33067(opens NVD record) | High | 8.4 | Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | Jun 10, 2025 |
| CVE-2025-33066(opens NVD record) | High | 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | Jun 10, 2025 |
| CVE-2025-33065(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-33064(opens NVD record) | High | 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | Jun 10, 2025 |
| CVE-2025-33063(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-33062(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-33061(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-33060(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-33059(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-33058(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-33057(opens NVD record) | Medium | 6.5 | Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network. | Jun 10, 2025 |
| CVE-2025-33056(opens NVD record) | High | 7.5 | Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network. | Jun 10, 2025 |
| CVE-2025-33055(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-33053(opens NVD record) | High | 8.8 | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | Jun 10, 2025 |
| CVE-2025-33052(opens NVD record) | Medium | 5.5 | Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-33050(opens NVD record) | High | 7.5 | Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Jun 10, 2025 |
| CVE-2025-32725(opens NVD record) | High | 7.5 | Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | Jun 10, 2025 |
| CVE-2025-32724(opens NVD record) | High | 7.5 | Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | Jun 10, 2025 |
| CVE-2025-32722(opens NVD record) | Medium | 5.5 | Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-32721(opens NVD record) | High | 7.3 | Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally. | Jun 10, 2025 |
| CVE-2025-32720(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-32719(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-32718(opens NVD record) | High | 7.8 | Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally. | Jun 10, 2025 |
| CVE-2025-32716(opens NVD record) | High | 7.8 | Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally. | Jun 10, 2025 |
| CVE-2025-32715(opens NVD record) | Medium | 6.5 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | Jun 10, 2025 |
| CVE-2025-32714(opens NVD record) | High | 7.8 | Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally. | Jun 10, 2025 |
| CVE-2025-32713(opens NVD record) | High | 7.8 | Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | Jun 10, 2025 |
| CVE-2025-32712(opens NVD record) | High | 7.8 | Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | Jun 10, 2025 |
| CVE-2025-32710(opens NVD record) | High | 8.1 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | Jun 10, 2025 |
| CVE-2025-31104(opens NVD record) | High | 7.2 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 through 7.2.7, 7.1.0 through 7.1.4, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated attacker to execute unauthorized code via crafted HTTP requests. | Jun 10, 2025 |
| CVE-2025-30321(opens NVD record) | Medium | 5.5 | InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 10, 2025 |
| CVE-2025-30317(opens NVD record) | High | 7.8 | InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 10, 2025 |
| CVE-2025-29828(opens NVD record) | High | 8.1 | Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network. | Jun 10, 2025 |
| CVE-2025-25250(opens NVD record) | Medium | 4.3 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiSASE 25.1.c may allow an authenticated user to access full SSL-VPN settings via crafted URL. | Jun 10, 2025 |
| CVE-2025-24471(opens NVD record) | Medium | 6.5 | An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiClient via revoked certificate. | Jun 10, 2025 |
| CVE-2025-24069(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-24068(opens NVD record) | Medium | 5.5 | Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-24065(opens NVD record) | Medium | 5.5 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | Jun 10, 2025 |
| CVE-2025-22256(opens NVD record) | Medium | 6.3 | A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 through 1.4.1 allows attacker to improper access control via specially crafted HTTP requests | Jun 10, 2025 |
| CVE-2025-22254(opens NVD record) | Medium | 6.6 | An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6.1, FortiProxy 7.4.0 through 7.4.7, FortiWeb 7.6.0 through 7.6.1, FortiWeb 7.4.0 through 7.4.6 allows an authenticated attacker with at least read-only admin permissions to gain super-admin privileges via crafted requests to Node.js websocket module. | Jun 10, 2025 |
| CVE-2025-22251(opens NVD record) | Low | 3.1 | An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets. | Jun 10, 2025 |
| CVE-2024-54019(opens NVD record) | Medium | 4.8 | A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection. | Jun 10, 2025 |
| CVE-2024-50568(opens NVD record) | Medium | 5.9 | A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attacker with the knowledge of device specific data to spoof the identity of a downstream device of the security fabric via crafted TCP requests. | Jun 10, 2025 |
| CVE-2024-50562(opens NVD record) | Medium | 4.8 | An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out. | Jun 10, 2025 |
| CVE-2024-45329(opens NVD record) | Medium | 4.3 | A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticated attacker to view unauthorized device information via key modification in API requests. | Jun 10, 2025 |
| CVE-2024-32119(opens NVD record) | Medium | 4.8 | An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests. | Jun 10, 2025 |
| CVE-2023-48786(opens NVD record) | Medium | 4.3 | A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests. | Jun 10, 2025 |
| CVE-2023-29184(opens NVD record) | Low | 3.2 | An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker to add SSH key files on the system silently via crafted CLI requests. | Jun 10, 2025 |