CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2025-64658

    Last Modified: 20 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7
    High

    CVE-2025-62573

    Last Modified: 20 Apr 2026

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62572

    Last Modified: 20 Apr 2026

    Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62571

    Last Modified: 20 Apr 2026

    Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62564

    Last Modified: 20 Apr 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62563

    Last Modified: 20 Apr 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62562

    Last Modified: 20 Apr 2026

    Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62561

    Last Modified: 20 Apr 2026

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-62549

    Last Modified: 20 Apr 2026

    Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-62473

    Last Modified: 20 Apr 2026

    Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62472

    Last Modified: 20 Apr 2026

    Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62470

    Last Modified: 20 Apr 2026

    Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7
    High

    CVE-2025-62469

    Last Modified: 20 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62466

    Last Modified: 20 Apr 2026

    Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62458

    Last Modified: 20 Apr 2026

    Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62457

    Last Modified: 20 Apr 2026

    Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-62456

    Last Modified: 20 Apr 2026

    Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-62454

    Last Modified: 20 Apr 2026

    Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-33214

    Last Modified: 15 Apr 2026

    NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-33213

    Last Modified: 15 Apr 2026

    NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

    Published: 9 Dec 2025
    7.1
    High

    CVE-2025-64784

    Last Modified: 10 Dec 2025

    DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive memory information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Dec 2025
    5.5
    Medium

    CVE-2025-64894

    Last Modified: 10 Dec 2025

    DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to application denial-of-service. An attacker could exploit this issue to cause the application to crash or become unresponsive. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Dec 2025
    7.1
    High

    CVE-2025-64893

    Last Modified: 10 Dec 2025

    DNG SDK versions 1.7.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure or application denial of service. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Dec 2025
    7.8
    High

    CVE-2025-64783

    Last Modified: 10 Dec 2025

    DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Dec 2025
    6.6
    Medium

    CVE-2025-46636

    Last Modified: 10 Dec 2025

    Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

    Published: 9 Dec 2025
    7.3
    High

    CVE-2025-46637

    Last Modified: 26 Feb 2026

    Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local malicious user could potentially exploit this vulnerability, leading to Elevation of privileges.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-13924

    Last Modified: 21 Apr 2026

    The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.17. This is due to missing or incorrect nonce validation on the 'maybe_duplicate' function. This makes it possible for unauthenticated attackers to duplicate and publish product field groups, including draft and pending field groups, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 9 Dec 2025
    6.6
    Medium

    CVE-2024-47570

    Last Modified: 26 Feb 2026

    An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.11; FortiPAM 1.4 all versions, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiSRA 1.4 all versions may allow a read-only administrator to retrieve API tokens of other administrators via observing REST API logs, if REST API logging is enabled (non-default configuration).

    Published: 9 Dec 2025
    9.8
    Critical

    CVE-2025-59718

    Last Modified: 9 Jun 2026

    A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

    Published: 9 Dec 2025
    9.8
    Critical

    CVE-2025-59719

    Last Modified: 9 Jun 2026

    An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.

    Published: 9 Dec 2025
    7.2
    High

    CVE-2025-53679

    Last Modified: 26 Feb 2026

    An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox Cloud 24.1, FortiSandbox Cloud 23 all versions allows a remote privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.

    Published: 9 Dec 2025
    5.4
    Medium

    CVE-2025-54353

    Last Modified: 14 Jan 2026

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an attacker to perform an XSS attack via crafted HTTP requests.

    Published: 9 Dec 2025
    7.2
    High

    CVE-2025-53949

    Last Modified: 26 Feb 2026

    An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-59810

    Last Modified: 14 Jan 2026

    An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow information disclosure to an authenticated attacker via crafted requests

    Published: 9 Dec 2025
    6.8
    Medium

    CVE-2025-59808

    Last Modified: 14 Jan 2026

    An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an attacker who has already gained access to a victim's user account to reset the account credentials without being prompted for the account's password

    Published: 9 Dec 2025
    6.8
    Medium

    CVE-2025-54838

    Last Modified: 14 Jan 2026

    An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.

    Published: 9 Dec 2025
    5.6
    Medium

    CVE-2025-62631

    Last Modified: 12 May 2026

    An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSLVPN session not terminated after a user's password change under particular conditions outside of the attacker's control

    Published: 9 Dec 2025
    2.7
    Low

    CVE-2025-57823

    Last Modified: 14 Jan 2026

    A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least sponsor permissions to read and download device logs via accessing specific endpoints

    Published: 9 Dec 2025
    7.2
    High

    CVE-2025-64153

    Last Modified: 14 Jan 2026

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via a specific HTTP request.

    Published: 9 Dec 2025
    2.7
    Low

    CVE-2025-59923

    Last Modified: 14 Jan 2026

    An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-only admin permission to obtain the credentials of other administrators' messaging services via crafted requests.

    Published: 9 Dec 2025
    7.2
    High

    CVE-2025-64156

    Last Modified: 26 Feb 2026

    An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7, FortiVoice 6.4 all versions, FortiVoice 6.0 all versions may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted requests

    Published: 9 Dec 2025
    4.9
    Medium

    CVE-2025-64471

    Last Modified: 14 Jan 2026

    A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to use the hash in place of the password to authenticate via crafted HTTP/HTTPS requests

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-60024

    Last Modified: 26 Feb 2026

    Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 may allow a privileged authenticated attacker to write arbitrary files via specifically HTTP or HTTPS commands

    Published: 9 Dec 2025
    8.1
    High

    CVE-2025-64447

    Last Modified: 26 Feb 2026

    A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker to execute arbitrary operations on the system via crafted HTTP or HTTPS request via forged cookies, requiring prior knowledge of the FortiWeb serial number.

    Published: 9 Dec 2025
    4.4
    Medium

    CVE-2025-12946

    Last Modified: 26 Feb 2026

    A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can allow attackers on the router's WAN side, using attacker-in-the-middle techniques (MiTM) to manipulate DNS responses and execute commands when speedtests are run. This issue affects RS700: through 1.0.7.82; RAX54Sv2 : before V1.1.6.36; RAX41v2: before V1.1.6.36; RAX50: before V1.2.14.114; RAXE500: before V1.2.14.114; RAX41: before V1.0.17.142; RAX43: before V1.0.17.142; RAX35v2: before V1.0.17.142; RAXE450: before V1.2.14.114; RAX43v2: before V1.1.6.36; RAX42: before V1.0.17.142; RAX45: before V1.0.17.142; RAX50v2: before V1.1.6.36; MR90: before V1.0.2.46; MS90: before V1.0.2.46; RAX42v2: before V1.1.6.36; RAX49S: before V1.1.6.36.

    Published: 9 Dec 2025
    1.1
    Low

    CVE-2025-12945

    Last Modified: 26 Aug 2026

    An improper input validation vulnerability in the NETGEAR Nighthawk R7000P (end of service) routers lets an authenticated administrator with local network access to the device, to execute OS command injections and make unauthorized modifications to the router software and functionality impacting its integrity. There is no additional impact to confidentiality or availability. This issue affects R7000P: through 1.3.3.154.

    Published: 9 Dec 2025
    5
    Medium

    CVE-2025-12941

    Last Modified: 16 Jan 2026

    Denial of Service Vulnerability in NETGEAR C6220 and C6230 (DOCSIS® 3.0 Two-in-one Cable Modem + WiFi Router) allows authenticated local WiFi users reboot the router.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2022-46845

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Essential Plugin Slider a SlidersPack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider a SlidersPack: from n/a before 2.3.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2022-47425

    Last Modified: 30 Jan 2026

    Missing Authorization vulnerability in Repute Infosystems ARMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ARMember: from n/a through 3.4.10.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2023-22675

    Last Modified: 15 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Taylor Hawkes WP Fast Cache allows Cross Site Request Forgery.This issue affects WP Fast Cache: from n/a through 1.5.

    Published: 9 Dec 2025