CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 7.8 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.5 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
| 1mo ago | 7.8 | Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.5 | Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. |
| 1mo ago | 7.5 | Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network. |
| 1mo ago | 8.8 | Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. |
| 1mo ago | 7.8 | Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 8.8 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
| 1mo ago | 8.8 | Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. |
| 1mo ago | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| 1mo ago | 8.4 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7.8 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| 1mo ago | 8 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. |
| 1mo ago | 8.4 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
| 1mo ago | 8.4 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7.8 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
| 1mo ago | 8.8 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| 1mo ago | 8.1 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
| 1mo ago | 7.2 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests. |
| 1mo ago | 7.4 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full system compromise. |
| Exploit 1mo ago | 7.4 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK does not perform checks on input values potentially resulting in stack overflow. This could allow an attacker to perform code execution and denial of service. |
| Exploit 1mo ago | 7.4 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). An out-of-bounds write vulnerability exists in SICAM SIAPP SDK. This could allow an attacker to write data beyond the intended buffer, potentially leading to denial of service, or arbitrary code execution. |
| 1mo ago | 7.8 | Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 8.8 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network. |
| 1mo ago | 7.8 | Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.5 | Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network. |
| 1mo ago | 7 | Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |