CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2025-20043

    Last Modified: 15 Apr 2026

    Uncontrolled search path for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2025-20041

    Last Modified: 15 Apr 2026

    Uncontrolled search path for some Intel(R) Graphics software for Intel(R) Arc™ graphics and Intel(R) Iris(R) Xe graphics before version 32.0.101.6325/32.0.101.6252 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 May 2025
    6.9
    Medium

    CVE-2025-20039

    Last Modified: 10 Sept 2025

    Race condition for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 13 May 2025
    5.6
    Medium

    CVE-2025-20034

    Last Modified: 15 Apr 2026

    Improper input validation in the BackupBiosUpdate UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50FCP boards before version R01.02.0003 may allow a privileged user to potentially enable information disclosure via local access.

    Published: 13 May 2025
    8.3
    High

    CVE-2025-20032

    Last Modified: 10 Sept 2025

    Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a privileged user to potentially enable denial of service via local access.

    Published: 13 May 2025
    6.8
    Medium

    CVE-2025-20031

    Last Modified: 15 Apr 2026

    Improper input validation for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.

    Published: 13 May 2025
    2.1
    Low

    CVE-2025-20030

    Last Modified: 15 Apr 2026

    Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable information disclosure via adjacent access.

    Published: 13 May 2025
    7
    High

    CVE-2025-20026

    Last Modified: 10 Sept 2025

    Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 13 May 2025
    5.8
    Medium

    CVE-2025-20022

    Last Modified: 15 Apr 2026

    Insufficient control flow management for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow a privileged user to potentially enable information disclosure via adjacent access.

    Published: 13 May 2025
    6.9
    Medium

    CVE-2025-20018

    Last Modified: 15 Apr 2026

    Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2025-20015

    Last Modified: 15 Apr 2026

    Uncontrolled search path element for some Intel(R) Ethernet Connection software before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 May 2025
    4.8
    Medium

    CVE-2025-20013

    Last Modified: 15 Apr 2026

    Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 13 May 2025
    4.1
    Medium

    CVE-2025-20012

    Last Modified: 15 Apr 2026

    Incorrect behavior order for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enable information disclosure via physical access.

    Published: 13 May 2025
    5.6
    Medium

    CVE-2025-20009

    Last Modified: 15 Apr 2026

    Improper input validation in the UEFI firmware GenerationSetup module for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable information disclosure via local access.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2025-20008

    Last Modified: 15 Apr 2026

    Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 May 2025
    8.3
    High

    CVE-2025-20006

    Last Modified: 10 Sept 2025

    Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

    Published: 13 May 2025
    8.5
    High

    CVE-2025-20004

    Last Modified: 15 Apr 2026

    Insufficient control flow management in the Alias Checking Trusted Module for some Intel(R) Xeon(R) 6 processor E-Cores firmware may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 13 May 2025
    7.3
    High

    CVE-2025-20003

    Last Modified: 15 Apr 2026

    Improper link resolution before file access ('Link Following') for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 13 May 2025
    Unknown

    CVE-2025-4668

    Last Modified: 13 May 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 13 May 2025
    8.4
    High

    CVE-2025-43565

    Last Modified: 26 Feb 2026

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.

    Published: 13 May 2025
    9.1
    Critical

    CVE-2025-43559

    Last Modified: 26 Feb 2026

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

    Published: 13 May 2025
    9.1
    Critical

    CVE-2025-43562

    Last Modified: 26 Feb 2026

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

    Published: 13 May 2025
    6.8
    Medium

    CVE-2025-43566

    Last Modified: 19 May 2025

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.

    Published: 13 May 2025
    9.1
    Critical

    CVE-2025-43564

    Last Modified: 26 Feb 2026

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed

    Published: 13 May 2025
    9.1
    Critical

    CVE-2025-43560

    Last Modified: 26 Feb 2026

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

    Published: 13 May 2025
    9.1
    Critical

    CVE-2025-43563

    Last Modified: 26 Feb 2026

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed.

    Published: 13 May 2025
    9.1
    Critical

    CVE-2025-43561

    Last Modified: 26 Feb 2026

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

    Published: 13 May 2025
    6.1
    Medium

    CVE-2025-30315

    Last Modified: 19 May 2025

    Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2025-30316

    Last Modified: 19 May 2025

    Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 13 May 2025
    6.1
    Medium

    CVE-2025-30314

    Last Modified: 19 May 2025

    Adobe Connect versions 12.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

    Published: 13 May 2025
    9.3
    Critical

    CVE-2025-43567

    Last Modified: 26 Feb 2026

    Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43554

    Last Modified: 19 May 2025

    Substance3D - Modeler versions 1.21.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43553

    Last Modified: 19 May 2025

    Substance3D - Modeler versions 1.21.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. If the application relies on a search path to locate critical resources such as libraries or executables, an attacker could manipulate the search path to load a malicious resource, potentially executing arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43569

    Last Modified: 26 Feb 2026

    Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43571

    Last Modified: 26 Feb 2026

    Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43570

    Last Modified: 26 Feb 2026

    Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    5.5
    Medium

    CVE-2025-43551

    Last Modified: 19 May 2025

    Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43568

    Last Modified: 26 Feb 2026

    Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43549

    Last Modified: 26 Feb 2026

    Substance3D - Stager versions 3.1.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43572

    Last Modified: 26 Feb 2026

    Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43548

    Last Modified: 26 Feb 2026

    Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.6
    High

    CVE-2025-3744

    Last Modified: 15 May 2025

    Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43547

    Last Modified: 15 May 2025

    Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43546

    Last Modified: 15 May 2025

    Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43545

    Last Modified: 15 May 2025

    Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-30330

    Last Modified: 15 May 2025

    Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    5.5
    Medium

    CVE-2025-30329

    Last Modified: 15 May 2025

    Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43557

    Last Modified: 15 May 2025

    Animate versions 24.0.8, 23.0.11 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43556

    Last Modified: 15 May 2025

    Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-43555

    Last Modified: 15 May 2025

    Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025