Search

Search Results (318615 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-60714 1 Microsoft 15 Windows, Windows 10, Windows 10 1607 and 12 more 2025-11-17 7.8 High
Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.
CVE-2025-60715 1 Microsoft 19 Remote, Windows, Windows 10 and 16 more 2025-11-17 8 High
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
CVE-2025-60716 1 Microsoft 14 Directx, Windows 10, Windows 10 1809 and 11 more 2025-11-17 7 High
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVE-2025-60717 1 Microsoft 14 Windows, Windows 10, Windows 10 1809 and 11 more 2025-11-17 7 High
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
CVE-2025-60718 1 Microsoft 4 Windows, Windows 11, Windows 11 24h2 and 1 more 2025-11-17 7.8 High
Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
CVE-2025-60719 1 Microsoft 18 Windows, Windows 10, Windows 10 1607 and 15 more 2025-11-17 7 High
Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2025-60720 1 Microsoft 18 Windows, Windows 10, Windows 10 1607 and 15 more 2025-11-17 7.8 High
Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
CVE-2025-60721 1 Microsoft 4 Windows, Windows 11, Windows 11 24h2 and 1 more 2025-11-17 7.8 High
Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
CVE-2025-62216 1 Microsoft 5 365, 365 Apps, Office 2021 and 2 more 2025-11-17 7.8 High
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-62210 1 Microsoft 2 365, Dynamics 365 2025-11-17 8.7 High
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
CVE-2025-62211 1 Microsoft 2 365, Dynamics 365 2025-11-17 8.7 High
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
CVE-2025-62206 1 Microsoft 2 365, Dynamics 365 2025-11-17 6.5 Medium
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
CVE-2025-62214 1 Microsoft 2 Visual Studio, Visual Studio 2022 2025-11-17 6.7 Medium
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally.
CVE-2025-47179 1 Microsoft 4 Configuration Manager, Configuration Manager 2403, Configuration Manager 2409 and 1 more 2025-11-17 6.7 Medium
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.
CVE-2025-59504 1 Microsoft 2 Azure Monitor, Azure Monitor Agent 2025-11-17 7.3 High
Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.
CVE-2025-59499 1 Microsoft 5 Sql Server, Sql Server 2016, Sql Server 2017 and 2 more 2025-11-17 8.8 High
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-60726 1 Microsoft 10 365, 365 Apps, Excel and 7 more 2025-11-17 7.1 High
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-60722 2 Google, Microsoft 3 Android, Onedrive, Onenote For Android 2025-11-17 6.5 Medium
Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over a network.
CVE-2024-44630 1 Phpgurukul 1 Student Record System 2025-11-17 6.5 Medium
Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1, pyear1, board2, roll2, pyear2, sub1,marks1, sub2, course-short, income, category, ph, country, state, city, padd, cadd, and gender.
CVE-2025-60724 1 Microsoft 20 Graphics Component, Office, Office For Mac and 17 more 2025-11-17 9.8 Critical
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.