CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 8.1 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. |
| 1mo ago | 7.5 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. |
| 1mo ago | 7 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 8.8 | Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network. |
| 1mo ago | 7.8 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7.5 | Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. |
| 1mo ago | 7 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.3 | Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. |
| 1mo ago | 7.8 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 8.8 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. |
| 1mo ago | 8.8 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. |
| 1mo ago | 8.8 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. |
| 1mo ago | 7.8 | Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7 | Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.5 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. |
| 1mo ago | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Reflected XSS.This issue affects Widgetize Pages Light: from n/a through <= 3.0. |
| Exploit 1mo ago | 7.2 | Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on the underlying operating system. |
| Exploit 1mo ago | 7.2 | Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system. |
| 1mo ago | 7.5 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| Exploit 1mo ago | 7.8 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file. |
| Exploit 1mo ago | 7.8 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file. |
| Exploit 1mo ago | 7.8 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file. |
| Exploit 1mo ago | 7.8 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file. |
| Exploit 1mo ago | 7.8 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file. |