CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Microsoft Digest Authentication Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Microsoft Digest Authentication. This issue affects several versions of Windows Server, including 2008, 2008 R2, 2012, and 2012 R2. The vulnerability arises from a heap-based buffer overflow and an integer overflow, allowing authenticated attackers to send malicious logon requests to the target domain controller, potentially leading to unauthorized code execution.
Microsoft Digest Authentication Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in Microsoft Digest Authentication. This issue affects multiple versions of Windows Server and Windows 10. The vulnerability arises from a heap-based buffer overflow, allowing an authenticated attacker to send a malicious logon request to the target domain controller, potentially leading to unauthorized code execution.
Microsoft Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
A vulnerability has been identified in the Windows Win32 Kernel Subsystem that allows for elevation of privilege. This issue could enable an attacker to gain SYSTEM privileges on the affected system.
Microsoft Windows Kernel Security Feature Bypass Vulnerability
A security feature bypass vulnerability in the Windows Kernel has been identified. This vulnerability allows for the circumvention of security mechanisms, potentially leading to unauthorized access or modification of system resources.
Microsoft Windows Core Messaging Elevation of Privileges Vulnerability
A vulnerability allowing elevation of privileges has been identified in the Windows Core Messaging component. This issue could enable an attacker to gain SYSTEM privileges. The vulnerability affects multiple Windows versions, including Windows 10 (all versions), Windows 11 (all versions), Windows Server 2016, Windows Server 2022, and Windows Server 2025. The root cause is an untrusted pointer dereference, which could be exploited under certain conditions.
Microsoft Windows Internet Connection Sharing Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Internet Connection Sharing (ICS) on various Windows Server and Windows 10 and 11 versions. This vulnerability allows an attacker to send specially crafted packets that disrupt the availability of the ICS service, leading to a denial-of-service condition.
Microsoft Windows Active Directory Domain Services API Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the Windows Active Directory Domain Services API. This issue can lead to a degradation of service, causing disruptions in the normal functioning of the domain services.
Microsoft Windows Kerberos Denial-of-Service Vulnerability
A denial-of-service vulnerability in the Windows Kerberos implementation has been identified. This issue allows for a significant disruption of service, causing systems to become unresponsive or unavailable. The vulnerability is present in multiple versions of Windows Server and Windows 10, as well as in Windows 11 and Windows Server 2025.
Microsoft Windows Remote Desktop Configuration Service Tampering Vulnerability
A tampering vulnerability has been identified in the Windows Remote Desktop Configuration Service. This vulnerability allows unauthorized modification of network communications, potentially leading to unauthorized changes in remote desktop settings or behaviors.
Microsoft Windows Deployment Services Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Windows Deployment Services. This issue allows an authenticated attacker to disrupt the service, causing it to become unavailable. The vulnerability requires specific actions to be performed on the affected system, followed by convincing another user to interact with the Windows Deployment Services functionality.
Microsoft Windows NTFS Elevation of Privilege Vulnerability
An elevation of privilege vulnerability has been identified in the Windows NTFS file system. This vulnerability allows an attacker to gain unauthorized access to certain privileges, potentially leading to unauthorized actions or access within the system.
Microsoft PC Manager Elevation of Privilege Vulnerability
A vulnerability allowing elevation of privilege has been identified in Microsoft PC Manager. This issue arises from improper link resolution before file access, which could be exploited to gain SYSTEM privileges.
Microsoft Outlook Spoofing Vulnerability
A spoofing vulnerability has been identified in Microsoft Outlook. This issue allows an attacker to manipulate email content in a way that could mislead the recipient, potentially leading to unauthorized actions or information disclosure.
Microsoft Windows Internet Connection Sharing Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Internet Connection Sharing (ICS) on various Windows platforms. This vulnerability allows an attacker to send specially crafted packets that disrupt the availability of the ICS service, leading to a denial-of-service condition.
Microsoft Internet Connection Sharing Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Internet Connection Sharing (ICS). This issue can cause a disruption in service, although the specific details of how the denial-of-service occurs are not provided.
Microsoft Internet Connection Sharing Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Internet Connection Sharing (ICS). This issue can cause a disruption in service, although the specific details of how the denial-of-service condition is triggered are not provided.
Microsoft Windows RRAS Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the Routing and Remote Access Service (RRAS) on Windows. This issue allows an attacker to execute arbitrary code on the affected system.
Visual Studio Installer Elevation of Privilege Vulnerability
An elevation of privilege vulnerability has been identified in the Visual Studio Installer. This vulnerability allows an attacker to gain higher privileges than intended, potentially leading to unauthorized actions or access within the application.
Microsoft Windows Telephony Server Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Windows Telephony Server component. This issue allows an attacker to execute arbitrary code on the affected system. The vulnerability arises from a double-free error, which can be exploited by sending a request to a malicious server that returns harmful data, potentially leading to unauthorized code execution on the user's machine.
Microsoft Windows Telephony Service Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Windows Telephony Service. This issue allows an attacker to execute arbitrary code on the affected system.
Microsoft HPC Pack Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Microsoft High Performance Compute (HPC) Pack) 2016 and 2019. This vulnerability allows an attacker with access to the same network as the targeted clusters or nodes to send a specially crafted HTTPS request to the head node or a Linux compute node, potentially leading to unauthorized code execution on other connected clusters or nodes.
Microsoft Surface Security Feature Bypass Vulnerability
A security feature bypass vulnerability has been identified in various Microsoft Surface devices, including the Surface Pro 9 ARM, Surface Pro 8, Surface Laptop Go, Surface Go 2, Surface Hub 3, Surface Laptop 3 with Intel Processor, Surface Hub 2S, Surface Pro 7+, Surface Laptop 4 with AMD Processor, Surface Laptop Go 3, Surface Go 3, Surface Laptop Go 2, Surface Laptop 4 with Intel Processor, and Surface Windows Dev Kit. This vulnerability allows for a bypass of security features related to the hypervisor, which could potentially compromise the secure kernel and hypervisor on certain hardware by bypassing the Unified Extensible Firmware Interface (UEFI). The vulnerability requires user interaction, specifically a reboot, and can be exploited by gaining access to the restricted network where the affected device is located.
Microsoft Windows Telephony Service Remote Code Execution Vulnerability
A remote code execution vulnerability has been identified in the Windows Telephony Service. This vulnerability allows an attacker to execute arbitrary code on the affected system. It arises from a heap-based buffer overflow, where malicious data from a server could be processed in a way that allows code execution on the client's machine.
Microsoft Azure Network Watcher VM Extension Elevation of Privilege Vulnerability
An elevation of privilege vulnerability has been identified in the Azure Network Watcher VM Extension. This vulnerability allows an attacker to gain higher privileges than intended, potentially leading to unauthorized actions or access within the affected environment.
Microsoft Windows Core Messaging Elevation of Privileges Vulnerability
A vulnerability allowing elevation of privileges has been identified in the Windows Core Messaging component. This issue could be exploited by an attacker to gain SYSTEM privileges.
Microsoft Windows ReFS Deduplication Service Elevation of Privilege Vulnerability
An elevation of privilege vulnerability has been identified in the Windows Resilient File System (ReFS) Deduplication Service. This vulnerability allows an attacker to gain SYSTEM privileges by exploiting a double free condition. The issue arises from a race condition that can be manipulated to achieve unauthorized privilege escalation.
Microsoft Windows ReFS Deduplication Service Elevation of Privilege Vulnerability
An elevation of privilege vulnerability has been identified in the Windows Resilient File System (ReFS) Deduplication Service. This vulnerability allows an attacker to exploit a race condition, potentially leading to unauthorized access or privileges. It affects multiple Windows 11 ARM64-based systems, Windows 11 x64-based systems, Windows Server 2025, and Windows Server 2025 (Server Core installation).
Microsoft Message Queuing Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Microsoft Message Queuing (MSMQ). This issue allows attackers to send specially crafted network packets to an exposed MSMQ service, causing it to crash or become unresponsive. The vulnerability affects several versions of Windows Server and Windows 10.
Microsoft DHCP Client Service Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the DHCP Client Service. This issue can cause a disruption in service, leading to potential downtime or unavailability of network resources.
Adobe Illustrator Stack-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution
A stack-based buffer overflow vulnerability has been identified in Adobe Illustrator versions 29.1, 28.7.3 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as the victim must open a malicious file.
Adobe Photoshop Elements Privilege Escalation Vulnerability via Insecure Temporary File Creation
A vulnerability allowing privilege escalation has been identified in Adobe Photoshop Elements versions 2025.0 and earlier. This issue arises from the creation of temporary files in directories with incorrect permissions. Exploitation of this vulnerability requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Designer Out-of-Bounds Write Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing out-of-bounds write has been identified in Adobe Substance 3D Designer versions through 14.0.2. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Illustrator Integer Underflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing arbitrary code execution has been identified in Adobe Illustrator versions 29.1, 28.7.3 and earlier, due to an integer underflow (wrap or wraparound) issue. Exploitation of this vulnerability requires user interaction, as a victim must open a malicious file.
Adobe Illustrator Use-After-Free Vulnerability Leading to Arbitrary Code Execution
A use-after-free vulnerability has been identified in Adobe Illustrator versions 29.1, 28.7.3 and earlier. This vulnerability could allow for arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe InCopy Integer Underflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing integer underflow has been identified in Adobe InCopy versions 20.0, 19.5.1 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe Substance 3D Stager NULL Pointer Dereference Vulnerability Leading to Denial-of-Service
A NULL pointer dereference vulnerability has been identified in Adobe Substance 3D Stager versions through 3.1.0. This vulnerability can lead to a denial-of-service condition by causing the application to crash. Exploitation requires user interaction, as a victim must open a malicious file.
Atlassian Jira Cross-Site Request Forgery Vulnerability in Login Authentication
A cross-site request forgery (CSRF) vulnerability has been identified in Atlassian Jira versions 7.6.4 prior to 8.1.0. The issue arises because the login form does not require a CSRF token, allowing an attacker to log a user into the system under an unexpected account.
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability Allowing Privilege Escalation
A vulnerability allowing authentication bypass via an alternate path or channel has been identified in Fortinet FortiOS versions 7.0.0 to 7.0.16 and FortiProxy versions 7.2.0 to 7.2.12, as well as FortiOS 7.0.0 through 7.0.19. This vulnerability may enable a remote attacker to gain super-admin privileges by sending crafted CSF proxy requests.
Fortinet FortiPortal Improper Path Equivalence Vulnerability Allowing Source Code Disclosure
A vulnerability allowing improper resolution of path equivalence has been identified in Fortinet FortiPortal versions 7.4.0 to 7.4.2, 7.2.0 to 7.2.6, and 7.0.0 to 7.0.11. This vulnerability may enable a remote, unauthenticated attacker to retrieve source code by sending crafted HTTP requests.
Dell UCC Edge Blind Server-Side Request Forgery Vulnerability
A blind server-side request forgery (SSRF) vulnerability has been identified in Dell UCC Edge version 2.3.0. This vulnerability allows an unauthenticated attacker with local access to exploit the application by manipulating server-side requests, potentially leading to unauthorized actions or information disclosure on behalf of the server.
Adobe InDesign Desktop Integer Underflow Vulnerability Leading to Arbitrary Code Execution
A vulnerability allowing integer underflow has been identified in Adobe InDesign Desktop versions ID20.0, ID19.5.1 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe InDesign Desktop Out-of-Bounds Write Vulnerability Allowing Arbitrary Code Execution
A vulnerability allowing out-of-bounds write has been identified in Adobe InDesign Desktop versions ID20.0, ID19.5.1 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe InDesign Improper Input Validation Vulnerability Leading to Denial-of-Service
A denial-of-service vulnerability has been identified in Adobe InDesign Desktop versions ID20.0, ID19.5.1 and earlier. This issue arises from improper input validation, allowing an attacker to cause the application to crash. Exploitation of this vulnerability requires user interaction, as the victim must open a malicious file.
Adobe InDesign Desktop NULL Pointer Dereference Vulnerability Leading to Denial-of-Service
A NULL pointer dereference vulnerability has been identified in Adobe InDesign Desktop versions ID20.0, ID19.5.1 and earlier. This vulnerability could lead to a denial-of-service condition by causing the application to crash. Exploitation requires user interaction, as a victim must open a malicious file.
Adobe InDesign Desktop Out-of-Bounds Read Vulnerability Allowing Memory Disclosure
An out-of-bounds read vulnerability has been identified in Adobe InDesign Desktop versions ID20.0, ID19.5.1 and earlier. This vulnerability could lead to the disclosure of sensitive memory. An attacker could exploit this issue to bypass mitigations such as Address Space Layout Randomization (ASLR). Exploitation requires user interaction, as the victim must open a malicious file.
Adobe InDesign Desktop Heap-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution
A heap-based buffer overflow vulnerability has been identified in Adobe InDesign Desktop versions ID20.0, ID19.5.1 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as the victim must open a malicious file.
Adobe InDesign Desktop Out-of-Bounds Write Vulnerability Allowing Arbitrary Code Execution
A vulnerability allowing out-of-bounds write has been identified in Adobe InDesign Desktop versions ID20.0, ID19.5.1 and earlier. This vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file.
Lexmark Print Management Client Security Decision Vulnerability
A vulnerability has been identified in the Lexmark Print Management Client, stemming from a reliance on untrusted inputs in security decisions. This issue could potentially be exploited, although specific exploitation details are not provided.
Fortinet FortiClient for Mac Improper Authentication Vulnerability Allowing Unauthorized Access
A vulnerability exists in Fortinet FortiClient for Mac in versions 7.0.11 through 7.2.4, where improper authentication allows attackers to gain unauthorized access to macOS by exploiting the use of empty passwords.
Fortinet FortiAnalyzer Sensitive Information Disclosure Vulnerability
A vulnerability in Fortinet FortiAnalyzer versions 6.4.0 through 7.6.0 allows unauthorized actors to access sensitive information by manipulating filters. This exposure of information could be exploited by attackers to gain unauthorized insights or data.
