CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2025-30294

    Last Modified: 4 Sept 2025

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.

    Published: 8 Apr 2025
    8.2
    High

    CVE-2025-30289

    Last Modified: 26 Feb 2026

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application. Scope is changed.

    Published: 8 Apr 2025
    8.2
    High

    CVE-2025-30288

    Last Modified: 26 Feb 2026

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low privileged attacker with local access could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application and scope is changed.

    Published: 8 Apr 2025
    9.1
    Critical

    CVE-2025-24446

    Last Modified: 21 Apr 2025

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution. Exploitation of this issue does not require user interaction, but admin panel privileges are required, and scope is changed.

    Published: 8 Apr 2025
    9.1
    Critical

    CVE-2025-24447

    Last Modified: 23 Apr 2025

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user resulting in a High impact to Confidentiality and Integrity. Exploitation of this issue does not require user interaction.

    Published: 8 Apr 2025
    9.1
    Critical

    CVE-2025-30281

    Last Modified: 15 Jul 2025

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-30291

    Last Modified: 21 Apr 2025

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. A low privileged attacker with local access could leverage this vulnerability to gain access to sensitive information which could be used to further compromise the system or bypass security mechanisms. Exploitation of this issue does not require user interaction.

    Published: 8 Apr 2025
    8.4
    High

    CVE-2025-30285

    Last Modified: 21 Apr 2025

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.

    Published: 8 Apr 2025
    8.4
    High

    CVE-2025-30286

    Last Modified: 21 Apr 2025

    ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-30308

    Last Modified: 22 Apr 2025

    XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-30307

    Last Modified: 22 Apr 2025

    XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-30305

    Last Modified: 23 Apr 2025

    XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-30306

    Last Modified: 22 Apr 2025

    XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-30309

    Last Modified: 22 Apr 2025

    XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-30300

    Last Modified: 11 Apr 2025

    Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-30303

    Last Modified: 11 Apr 2025

    Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-30295

    Last Modified: 26 Feb 2026

    Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-30297

    Last Modified: 26 Feb 2026

    Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-30304

    Last Modified: 26 Feb 2026

    Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-30301

    Last Modified: 11 Apr 2025

    Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-30302

    Last Modified: 11 Apr 2025

    Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-30299

    Last Modified: 26 Feb 2026

    Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-30296

    Last Modified: 26 Feb 2026

    Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-30298

    Last Modified: 26 Feb 2026

    Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.4
    Medium

    CVE-2025-27205

    Last Modified: 5 Aug 2025

    Adobe Experience Manager Screens versions FP11.3 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. Exploitation of this issue requires user interaction in that a victim must open a malicious link.

    Published: 8 Apr 2025
    4.2
    Medium

    CVE-2025-32036

    Last Modified: 26 Aug 2025

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. The algorithm used to generate the captcha image shows the least complexity of the desired image. For this reason, the created image can be easily read by OCR tools, and the intruder can send automatic requests by building a robot and using this tool. This vulnerability is fixed in 9.13.8.

    Published: 8 Apr 2025
    2.6
    Low

    CVE-2025-32035

    Last Modified: 26 Aug 2025

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's possible to e.g. upload an executable file renamed to be a .jpg. This file could then be executed by another security vulnerability. This vulnerability is fixed in 9.13.2.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-27201

    Last Modified: 15 Apr 2025

    Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27200

    Last Modified: 26 Feb 2026

    Animate versions 24.0.7, 23.0.10 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27199

    Last Modified: 26 Feb 2026

    Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-27202

    Last Modified: 15 Apr 2025

    Animate versions 24.0.7, 23.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27198

    Last Modified: 26 Feb 2026

    Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27196

    Last Modified: 26 Feb 2026

    Premiere Pro versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27193

    Last Modified: 26 Feb 2026

    Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27195

    Last Modified: 26 Feb 2026

    Media Encoder versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27194

    Last Modified: 26 Feb 2026

    Media Encoder versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-27184

    Last Modified: 18 Apr 2025

    After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27182

    Last Modified: 26 Feb 2026

    After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-27186

    Last Modified: 18 Apr 2025

    After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-27185

    Last Modified: 18 Apr 2025

    After Effects versions 25.1, 24.6.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-27187

    Last Modified: 18 Apr 2025

    After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27183

    Last Modified: 26 Feb 2026

    After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-27204

    Last Modified: 15 Apr 2025

    After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-24062

    Last Modified: 13 Feb 2026

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-24060

    Last Modified: 13 Feb 2026

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-29811

    Last Modified: 13 Feb 2026

    Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    6.2
    Medium

    CVE-2025-29819

    Last Modified: 13 Feb 2026

    External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-29816

    Last Modified: 13 Feb 2026

    Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-29812

    Last Modified: 13 Feb 2026

    Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-29810

    Last Modified: 13 Feb 2026

    Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

    Published: 8 Apr 2025