Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
31,739 matching · page 533/635Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2025-4478(opens NVD record) | Medium | 6.5 | A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system. | May 16, 2025 |
| CVE-2025-37890(opens NVD record) | High | 7.8 | In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc As described in Gerrard's report [1], we have a UAF case when an hfsc class has a netem child qdisc. The crux of the issue is that hfsc is assuming that checking for cl->qdisc->q.qlen == 0 guarantees that it hasn't inserted the class in the vttree or eltree (which is not true for the netem duplicate case). This patch checks the n_active class variable to make sure that the code won't insert the class in the vttree or eltree twice, catering for the reentrant case. [1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/ | May 16, 2025 |
| CVE-2024-51475(opens NVD record) | Medium | 5.4 | IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | May 16, 2025 |
| CVE-2025-1138(opens NVD record) | Medium | 4.3 | IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing. | May 15, 2025 |
| CVE-2025-47161(opens NVD record) | High | 7.8 | Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | May 15, 2025 |
| CVE-2025-30476(opens NVD record) | Medium | 5.3 | Dell PowerScale InsightIQ, version 5.2, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | May 15, 2025 |
| CVE-2025-30475(opens NVD record) | High | 8.1 | Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges. | May 15, 2025 |
| CVE-2025-26481(opens NVD record) | High | 7.5 | Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to denial of service. | May 15, 2025 |
| CVE-2025-3440(opens NVD record) | Medium | 5.5 | IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | May 15, 2025 |
| CVE-2025-4516(opens NVD record) | Unscored | — | There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError. | May 15, 2025 |
| CVE-2025-25370(opens NVD record) | Medium | 4.6 | An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically proximate attacker to obtain sensitive information via the show app only setting function. | May 14, 2025 |
| CVE-2025-33104(opens NVD record) | Medium | 4.4 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | May 14, 2025 |
| CVE-2025-2900(opens NVD record) | High | 7.5 | IBM Semeru Runtime 8.0.302.0 through 8.0.442.0, 11.0.12.0 through 11.0.26.0, 17.0.0.0 through 17.0.14.0, and 21.0.0.0 through 12.0.6.0 is vulnerable to a denial of service caused by a buffer overflow and subsequent crash, due to a defect in its native AES/CBC encryption implementation. | May 14, 2025 |
| CVE-2025-0135(opens NVD record) | Low | 3.3 | An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non administrative user to disable the app. The GlobalProtect app on Windows, Linux, iOS, Android, Chrome OS and GlobalProtect UWP app are not affected. | May 14, 2025 |
| CVE-2025-0130(opens NVD record) | High | 7.5 | A missing exception check in Palo Alto Networks PAN-OS® software with the web proxy feature enabled allows an unauthenticated attacker to send a burst of maliciously crafted packets that causes the firewall to become unresponsive and eventually reboot. Repeated successful attempts to trigger this condition will cause the firewall to enter maintenance mode. This issue does not affect Cloud NGFW or Prisma Access. | May 14, 2025 |
| CVE-2025-3600(opens NVD record) | High | 7.5 | In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service. | May 14, 2025 |
| CVE-2024-57273(opens NVD record) | Medium | 5.4 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and a derivable device key generated from the public SSH key. | May 14, 2025 |
| CVE-2025-3834(opens NVD record) | High | 8.1 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report. | May 14, 2025 |
| CVE-2025-3833(opens NVD record) | High | 8.1 | Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports. | May 14, 2025 |
| CVE-2025-26646(opens NVD record) | High | 8.0 | External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. | May 13, 2025 |
| CVE-2025-43572(opens NVD record) | High | 7.8 | Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43571(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43570(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43569(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43568(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43551(opens NVD record) | Medium | 5.5 | Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43549(opens NVD record) | High | 7.8 | Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43548(opens NVD record) | High | 7.8 | Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2024-28956(opens NVD record) | Medium | 5.6 | Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | May 13, 2025 |
| CVE-2025-4660(opens NVD record) | Critical | 9.8 | A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent. This does not impact Linux or OSX Secure Connector. | May 13, 2025 |
| CVE-2025-43557(opens NVD record) | High | 7.8 | Animate versions 24.0.8, 23.0.11 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43556(opens NVD record) | High | 7.8 | Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43555(opens NVD record) | High | 7.8 | Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43547(opens NVD record) | High | 7.8 | Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43546(opens NVD record) | High | 7.8 | Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-43545(opens NVD record) | High | 7.8 | Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-30330(opens NVD record) | High | 7.8 | Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-30329(opens NVD record) | Medium | 5.5 | Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-30328(opens NVD record) | High | 7.8 | Animate versions 24.0.8, 23.0.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-30325(opens NVD record) | High | 7.8 | Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-30324(opens NVD record) | High | 7.8 | Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 13, 2025 |
| CVE-2025-32709(opens NVD record) | High | 7.8 | Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | May 13, 2025 |
| CVE-2025-32707(opens NVD record) | High | 7.8 | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | May 13, 2025 |
| CVE-2025-32706(opens NVD record) | High | 7.8 | Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | May 13, 2025 |
| CVE-2025-32705(opens NVD record) | High | 7.8 | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-32704(opens NVD record) | High | 8.4 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-32703(opens NVD record) | Medium | 5.5 | Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. | May 13, 2025 |
| CVE-2025-32702(opens NVD record) | High | 7.8 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally. | May 13, 2025 |
| CVE-2025-32701(opens NVD record) | High | 7.8 | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | May 13, 2025 |
| CVE-2025-30400(opens NVD record) | High | 7.8 | Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | May 13, 2025 |