CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-54283

    Last Modified: 26 Feb 2026

    Illustrator versions 29.7, 28.7.9 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-54284

    Last Modified: 26 Feb 2026

    Illustrator versions 29.7, 28.7.9 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2025
    8.5
    High

    CVE-2025-59429

    Last Modified: 13 Feb 2026

    FreePBX is an open source GUI for managing Asterisk. In versions prior to 16.0.68.39 for FreePBX 16 and versions prior to 17.0.18.38 for FreePBX 17, a reflected cross-site scripting vulnerability is present on the Asterisk HTTP Status page. The Asterisk HTTP status page is exposed by FreePBX and is available by default on version 16 via any bound IP address at port 8088. By default on version 17, the binding is only to localhost IP, making it significantly less vulnerable. The vulnerability can be exploited by unauthenticated attackers to obtain cookies from logged-in users, allowing them to hijack a session of an administrative user. The theft of admin session cookies allows attackers to gain control over the FreePBX admin interface, enabling them to access sensitive data, modify system configurations, create backdoor accounts, and cause service disruption. This issue has been patched in version 16.0.68.39 for FreePBX 16 and version 17.0.18.38 for FreePBX 17.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-33177

    Last Modified: 15 Apr 2026

    NVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could allow a local attacker to cause memory overallocation. A successful exploitation of this vulnerability might lead to denial of service.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-54282

    Last Modified: 26 Feb 2026

    Adobe Framemaker versions 2020.9, 2022.7 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-54281

    Last Modified: 26 Feb 2026

    Adobe Framemaker versions 2020.9, 2022.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2025
    8.6
    High

    CVE-2025-59051

    Last Modified: 15 Apr 2026

    The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device discovery. In Endpoint Manager 16 before 16.0.92 and 17 before 17.0.6, insufficiently sanitized user-supplied input allows authenticated OS command execution as the asterisk user. Authentication with a known username is required. Updating to Endpoint Manager 16.0.92 or 17.0.6 addresses the issue.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-54276

    Last Modified: 26 Feb 2026

    Substance3D - Modeler versions 1.22.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2025
    7.6
    High

    CVE-2025-33182

    Last Modified: 15 Apr 2026

    NVIDIA Jetson Linux contains a vulnerability in UEFI, where improper authentication may allow a privileged user to cause corruption of the Linux Device Tree. A successful exploitation of this vulnerability might lead to data tampering, denial of service.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-54274

    Last Modified: 26 Feb 2026

    Substance3D - Viewer versions 0.25.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-54273

    Last Modified: 26 Feb 2026

    Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-54275

    Last Modified: 14 Oct 2025

    Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this vulnerability to crash the application or make it unavailable. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-54280

    Last Modified: 26 Feb 2026

    Substance3D - Viewer versions 0.25.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Oct 2025
    8.4
    High

    CVE-2025-23356

    Last Modified: 15 Apr 2026

    NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-11736

    Last Modified: 21 Oct 2025

    A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /index.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

    Published: 14 Oct 2025
    7.7
    High

    CVE-2025-8459

    Last Modified: 22 Oct 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Monitoring recurrent downtime scheduler modules) allows Stored XSS.This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.

    Published: 14 Oct 2025
    4.9
    Medium

    CVE-2025-37145

    Last Modified: 12 Nov 2025

    Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-59497

    Last Modified: 22 Feb 2026

    Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-59289

    Last Modified: 22 Feb 2026

    Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    9.8
    Critical

    CVE-2025-59287

    Last Modified: 26 Feb 2026

    Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-59285

    Last Modified: 26 Feb 2026

    Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59278

    Last Modified: 22 Feb 2026

    Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59275

    Last Modified: 22 Feb 2026

    Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    4.9
    Medium

    CVE-2025-37144

    Last Modified: 12 Nov 2025

    Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-59261

    Last Modified: 22 Feb 2026

    Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-59260

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-59253

    Last Modified: 22 Feb 2026

    Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59230

    Last Modified: 26 Feb 2026

    Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.5
    High

    CVE-2025-59248

    Last Modified: 15 Jun 2026

    Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-59244

    Last Modified: 22 Feb 2026

    External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59241

    Last Modified: 26 Feb 2026

    Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59238

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7.1
    High

    CVE-2025-59232

    Last Modified: 22 Feb 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-59229

    Last Modified: 22 Feb 2026

    Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59227

    Last Modified: 22 May 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59226

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59225

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59224

    Last Modified: 22 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59223

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59222

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-59221

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-59214

    Last Modified: 27 Mar 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

    Published: 14 Oct 2025
    8.8
    High

    CVE-2025-59213

    Last Modified: 26 Feb 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network.

    Published: 14 Oct 2025
    7.4
    High

    CVE-2025-59210

    Last Modified: 22 Feb 2026

    Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-59209

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    7.1
    High

    CVE-2025-59208

    Last Modified: 22 Feb 2026

    Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-59205

    Last Modified: 22 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-59203

    Last Modified: 22 Feb 2026

    Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    5
    Medium

    CVE-2025-59198

    Last Modified: 22 Feb 2026

    Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-59197

    Last Modified: 22 Feb 2026

    Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025