CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| 1mo ago | 7.8 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7.8 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| 1mo ago | 8.4 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
| 1mo ago | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| 1mo ago | 7.8 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| 1mo ago | 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| 1mo ago | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| 1mo ago | 8.4 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
| Exploit 1mo ago | 7.8 | Substance3D - Painter versions 11.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
| Exploit 1mo ago | 7.8 | InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
| Exploit 1mo ago | 7.8 | InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
| Exploit 1mo ago | 7.8 | InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
| Exploit 1mo ago | 7.8 | InDesign Desktop versions ID20.2, ID19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |
| Exploit 1mo ago | 8.4 | IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input. |
| 1mo ago | 7.8 | Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally. |
| KEV 1mo ago | 8.8 | Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. |
| 1mo ago | 8.1 | Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. |
| 1mo ago | 8.1 | Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network. |
| 1mo ago | 7.5 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. |
| 1mo ago | 8.4 | Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally. |
| 1mo ago | 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
| 1mo ago | 8.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. |
| 1mo ago | 7.5 | Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network. |
| KEV 1mo ago | 8.8 | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. |
| 1mo ago | 7.5 | Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| 1mo ago | 7.5 | Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. |
| 1mo ago | 7.5 | Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. |
| 1mo ago | 7.3 | Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally. |