CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-27162

    Last Modified: 26 Feb 2026

    Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-27160

    Last Modified: 26 Feb 2026

    Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-27159

    Last Modified: 26 Feb 2026

    Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    5.5
    Medium

    CVE-2025-27163

    Last Modified: 26 Feb 2026

    Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-27169

    Last Modified: 26 Feb 2026

    Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-27167

    Last Modified: 31 Mar 2025

    Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that search path to point to a malicious program, which the targeted application would then execute. The problem extends to any type of critical resource that the application trusts.

    Published: 11 Mar 2025
    5.5
    Medium

    CVE-2025-27170

    Last Modified: 31 Mar 2025

    Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-27168

    Last Modified: 31 Mar 2025

    Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    5.5
    Medium

    CVE-2025-24449

    Last Modified: 28 Apr 2025

    Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    5.5
    Medium

    CVE-2025-24448

    Last Modified: 28 Apr 2025

    Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-27166

    Last Modified: 26 Feb 2026

    InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-27175

    Last Modified: 26 Feb 2026

    InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-27177

    Last Modified: 26 Feb 2026

    InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-27178

    Last Modified: 26 Feb 2026

    InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    5.5
    Medium

    CVE-2025-27176

    Last Modified: 14 Apr 2025

    InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24453

    Last Modified: 26 Feb 2026

    InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24452

    Last Modified: 26 Feb 2026

    InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-27171

    Last Modified: 28 Apr 2025

    InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    5.5
    Medium

    CVE-2025-27179

    Last Modified: 14 Apr 2025

    InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24444

    Last Modified: 1 Apr 2025

    Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24443

    Last Modified: 1 Apr 2025

    Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24441

    Last Modified: 1 Apr 2025

    Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24445

    Last Modified: 1 Apr 2025

    Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24442

    Last Modified: 1 Apr 2025

    Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24439

    Last Modified: 1 Apr 2025

    Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24440

    Last Modified: 26 Feb 2026

    Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24451

    Last Modified: 26 Feb 2026

    Substance3D - Painter versions 10.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24450

    Last Modified: 26 Feb 2026

    Substance3D - Painter versions 10.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Mar 2025
    8.5
    High

    CVE-2025-27440

    Last Modified: 22 Oct 2025

    Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

    Published: 11 Mar 2025
    8.5
    High

    CVE-2025-27439

    Last Modified: 22 Oct 2025

    Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

    Published: 11 Mar 2025
    8.5
    High

    CVE-2025-0151

    Last Modified: 22 Oct 2025

    Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access.

    Published: 11 Mar 2025
    7.1
    High

    CVE-2025-0150

    Last Modified: 1 Aug 2025

    Incorrect behavior order in some Zoom Workplace Apps for iOS before version 6.3.0 may allow an authenticated user to conduct a denial of service via network access.

    Published: 11 Mar 2025
    6.5
    Medium

    CVE-2025-0149

    Last Modified: 19 Aug 2025

    Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access.

    Published: 11 Mar 2025
    8.8
    High

    CVE-2025-26645

    Last Modified: 13 Feb 2026

    Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

    Published: 11 Mar 2025
    7
    High

    CVE-2025-26633

    Last Modified: 26 Feb 2026

    Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

    Published: 11 Mar 2025
    7.3
    High

    CVE-2025-26631

    Last Modified: 13 Feb 2026

    Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-26630

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-26629

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 11 Mar 2025
    7
    High

    CVE-2025-26627

    Last Modified: 13 Feb 2026

    Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.

    Published: 11 Mar 2025
    8.4
    High

    CVE-2025-24049

    Last Modified: 13 Feb 2026

    Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally.

    Published: 11 Mar 2025
    7.3
    High

    CVE-2025-24994

    Last Modified: 13 Feb 2026

    Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24993

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

    Published: 11 Mar 2025
    5.5
    Medium

    CVE-2025-24992

    Last Modified: 13 Feb 2026

    Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.

    Published: 11 Mar 2025
    5.5
    Medium

    CVE-2025-24991

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24985

    Last Modified: 26 Feb 2026

    Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

    Published: 11 Mar 2025
    4.6
    Medium

    CVE-2025-24984

    Last Modified: 26 Feb 2026

    Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

    Published: 11 Mar 2025
    7
    High

    CVE-2025-24983

    Last Modified: 26 Feb 2026

    Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

    Published: 11 Mar 2025
    8.4
    High

    CVE-2025-24084

    Last Modified: 13 Feb 2026

    Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.

    Published: 11 Mar 2025
    7.3
    High

    CVE-2025-24076

    Last Modified: 13 Feb 2026

    Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

    Published: 11 Mar 2025
    7.8
    High

    CVE-2025-24075

    Last Modified: 13 Feb 2026

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 11 Mar 2025