CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-30328

    Last Modified: 15 May 2025

    Animate versions 24.0.8, 23.0.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    8.7
    High

    CVE-2025-4660

    Last Modified: 21 Aug 2025

    A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based attacker to connect without authentication. By interacting with this pipe, an attacker can redirect the agent to communicate with a rogue server that can issue commands via the SecureConnector Agent.  This does not impact Linux or OSX Secure Connector.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-30325

    Last Modified: 22 May 2025

    Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-30326

    Last Modified: 15 May 2025

    Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-30324

    Last Modified: 22 May 2025

    Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-30322

    Last Modified: 19 May 2025

    Substance3D - Painter versions 11.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.3
    High

    CVE-2023-31359

    Last Modified: 26 Feb 2026

    Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

    Published: 13 May 2025
    7.3
    High

    CVE-2023-31358

    Last Modified: 26 Feb 2026

    A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-27197

    Last Modified: 22 May 2025

    Lightroom Desktop versions 8.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    5.5
    Medium

    CVE-2025-30320

    Last Modified: 14 May 2025

    InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-30318

    Last Modified: 14 May 2025

    InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    5.5
    Medium

    CVE-2025-30319

    Last Modified: 14 May 2025

    InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 13 May 2025
    7.3
    High

    CVE-2025-0035

    Last Modified: 15 Apr 2026

    Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution.

    Published: 13 May 2025
    2.3
    Low

    CVE-2025-47280

    Last Modified: 22 May 2025

    Umbraco Forms is a form builder that integrates with the Umbraco content management system. Starting in the 7.x branch and prior to versions 13.4.2 and 15.1.2, the 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any form with this workflow configured vulnerable, as it allows sending the message from a trusted system and address, potentially bypassing spam and email client security systems. This issue affects all (supported) versions Umbraco Forms and is patched in 13.4.2 and 15.1.2. Unpatched or unsupported versions can workaround this issue by using the `Send email with template (Razor)` workflow instead or writing a custom workflow type. To avoid accidentally using the vulnerable workflow again, the `SendEmail` workflow type can be removed using a composer available in the GitHub Security Advisory for this vulnerability.

    Published: 13 May 2025
    7.3
    High

    CVE-2024-36321

    Last Modified: 15 Apr 2026

    Unquoted search path within AIM-T Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution.

    Published: 13 May 2025
    6.9
    Medium

    CVE-2024-6364

    Last Modified: 19 Nov 2025

    A vulnerability in Absolute Persistence® versions before 2.8 exists when it is not activated. This may allow a skilled attacker with both physical access to the device, and full hostile network control, to initiate OS commands on the device. To remediate this vulnerability, update the device firmware to the latest available version. Please contact the device manufacturer for upgrade instructions or contact Absolute Security, see reference below.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-24063

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-32707

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-32705

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

    Published: 13 May 2025
    8.4
    High

    CVE-2025-32704

    Last Modified: 26 Feb 2026

    Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-32702

    Last Modified: 26 Feb 2026

    Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.

    Published: 13 May 2025
    7.5
    High

    CVE-2025-30397

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-30388

    Last Modified: 22 May 2026

    Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-30385

    Last Modified: 26 Feb 2026

    Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

    Published: 13 May 2025
    5.7
    Medium

    CVE-2025-29974

    Last Modified: 13 Feb 2026

    Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.

    Published: 13 May 2025
    8.8
    High

    CVE-2025-29963

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

    Published: 13 May 2025
    8.8
    High

    CVE-2025-29962

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

    Published: 13 May 2025
    6.5
    Medium

    CVE-2025-29961

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 13 May 2025
    6.5
    Medium

    CVE-2025-29958

    Last Modified: 13 Feb 2026

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 13 May 2025
    6.2
    Medium

    CVE-2025-29957

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.

    Published: 13 May 2025
    5.4
    Medium

    CVE-2025-29956

    Last Modified: 13 Feb 2026

    Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.

    Published: 13 May 2025
    6.2
    Medium

    CVE-2025-29955

    Last Modified: 13 Feb 2026

    Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.

    Published: 13 May 2025
    5.9
    Medium

    CVE-2025-29954

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

    Published: 13 May 2025
    7.5
    High

    CVE-2025-29842

    Last Modified: 26 Feb 2026

    Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network.

    Published: 13 May 2025
    7
    High

    CVE-2025-29841

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally.

    Published: 13 May 2025
    8.8
    High

    CVE-2025-29840

    Last Modified: 26 Feb 2026

    Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

    Published: 13 May 2025
    4
    Medium

    CVE-2025-29839

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.

    Published: 13 May 2025
    7.4
    High

    CVE-2025-29838

    Last Modified: 13 Feb 2026

    Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally.

    Published: 13 May 2025
    5.5
    Medium

    CVE-2025-29837

    Last Modified: 13 Feb 2026

    Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.

    Published: 13 May 2025
    6.5
    Medium

    CVE-2025-29836

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 13 May 2025
    6.5
    Medium

    CVE-2025-29835

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 13 May 2025
    7.7
    High

    CVE-2025-29833

    Last Modified: 26 Feb 2026

    Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.

    Published: 13 May 2025
    6.5
    Medium

    CVE-2025-29832

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 13 May 2025
    7.5
    High

    CVE-2025-29831

    Last Modified: 26 Feb 2026

    Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

    Published: 13 May 2025
    6.5
    Medium

    CVE-2025-29830

    Last Modified: 13 Feb 2026

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 13 May 2025
    5.5
    Medium

    CVE-2025-29829

    Last Modified: 13 Feb 2026

    Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.

    Published: 13 May 2025
    6.5
    Medium

    CVE-2025-26685

    Last Modified: 13 Feb 2026

    Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

    Published: 13 May 2025
    6.7
    Medium

    CVE-2025-27488

    Last Modified: 13 Feb 2026

    Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.

    Published: 13 May 2025
    7.5
    High

    CVE-2025-26677

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

    Published: 13 May 2025
    7.8
    High

    CVE-2025-32709

    Last Modified: 26 Feb 2026

    Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 13 May 2025