| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21407 | Hig | 0.57 | 8.8 | 0.02 | Feb 11, 2025 | Windows Telephony Service Remote Code Execution Vulnerability | ||
| CVE-2025-21406 | Hig | 0.57 | 8.8 | 0.02 | Feb 11, 2025 | Windows Telephony Service Remote Code Execution Vulnerability | ||
| CVE-2025-21400 | Hig | 0.54 | 8.0 | 0.34 | Feb 11, 2025 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2025-21397 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2025-21394 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2025-21392 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2025-21391 | Hig | 0.58 | 7.1 | 0.02 | KEV | Feb 11, 2025 | Windows Storage Elevation of Privilege Vulnerability | |
| CVE-2025-21390 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2025-21387 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2025-21386 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2025-21383 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Microsoft Excel Information Disclosure Vulnerability | ||
| CVE-2025-21381 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2025-21379 | Hig | 0.46 | 7.1 | 0.01 | Feb 11, 2025 | DHCP Client Service Remote Code Execution Vulnerability | ||
| CVE-2025-21376 | Hig | 0.53 | 8.1 | 0.09 | Feb 11, 2025 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2025-21375 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2025-21373 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2025-21371 | Hig | 0.57 | 8.8 | 0.02 | Feb 11, 2025 | Windows Telephony Service Remote Code Execution Vulnerability | ||
| CVE-2025-21369 | Hig | 0.57 | 8.8 | 0.02 | Feb 11, 2025 | Microsoft Digest Authentication Remote Code Execution Vulnerability | ||
| CVE-2025-21368 | Hig | 0.57 | 8.8 | 0.02 | Feb 11, 2025 | Microsoft Digest Authentication Remote Code Execution Vulnerability | ||
| CVE-2025-21367 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | ||
| CVE-2025-21359 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Windows Kernel Security Feature Bypass Vulnerability | ||
| CVE-2025-21358 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Windows Core Messaging Elevation of Privileges Vulnerability | ||
| CVE-2025-21351 | Hig | 0.49 | 7.5 | 0.02 | Feb 11, 2025 | Windows Active Directory Domain Services API Denial of Service Vulnerability | ||
| CVE-2025-21322 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2025 | Microsoft PC Manager Elevation of Privilege Vulnerability | ||
| CVE-2025-21208 | Hig | 0.57 | 8.8 | 0.02 | Feb 11, 2025 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2025-21206 | Hig | 0.48 | 7.3 | 0.01 | Feb 11, 2025 | Visual Studio Installer Elevation of Privilege Vulnerability | ||
| CVE-2025-21201 | Hig | 0.57 | 8.8 | 0.02 | Feb 11, 2025 | Windows Telephony Server Remote Code Execution Vulnerability | ||
| CVE-2025-21200 | Hig | 0.57 | 8.8 | 0.02 | Feb 11, 2025 | Windows Telephony Service Remote Code Execution Vulnerability | ||
| CVE-2025-21194 | Hig | 0.46 | 7.1 | 0.01 | Feb 11, 2025 | Microsoft Surface Security Feature Bypass Vulnerability | ||
| CVE-2025-21190 | Hig | 0.57 | 8.8 | 0.02 | Feb 11, 2025 | Windows Telephony Service Remote Code Execution Vulnerability | ||
| CVE-2025-21184 | Hig | 0.46 | 7.0 | 0.01 | Feb 11, 2025 | Windows Core Messaging Elevation of Privileges Vulnerability | ||
| CVE-2025-21183 | Hig | 0.48 | 7.4 | 0.01 | Feb 11, 2025 | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | ||
| CVE-2025-21182 | Hig | 0.48 | 7.4 | 0.01 | Feb 11, 2025 | Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability | ||
| CVE-2025-21181 | Hig | 0.49 | 7.5 | 0.03 | Feb 11, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2025-21163 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2025 | Illustrator versions 29.1, 28.7.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… | ||
| CVE-2025-21161 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2025 | Substance3D - Designer versions 14.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious… | ||
| CVE-2025-21160 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2025 | Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open… | ||
| CVE-2025-21159 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2025 | Illustrator versions 29.1, 28.7.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | ||
| CVE-2025-21156 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2025 | InCopy versions 20.0, 19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2025-24472 | Hig | 0.71 | 8.1 | 0.07 | KEV | Feb 11, 2025 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream… | |
| CVE-2025-24470 | Hig | 0.56 | 8.6 | 0.01 | Feb 11, 2025 | An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests. | ||
| CVE-2025-22399 | Hig | 0.51 | 7.9 | 0.00 | Feb 11, 2025 | Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Server-side request forgery | ||
| CVE-2025-21158 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2025 | InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim… | ||
| CVE-2025-21157 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2025 | InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2025-21123 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2025 | InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2025-21121 | Hig | 0.51 | 7.8 | 0.00 | Feb 11, 2025 | InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a… | ||
| CVE-2024-50567 | Hig | 0.47 | 7.2 | 0.02 | Feb 11, 2025 | An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input. | ||
| CVE-2024-40591 | Hig | 0.57 | 8.8 | 0.01 | Feb 11, 2025 | An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to… | ||
| CVE-2024-40584 | Hig | 0.47 | 7.2 | 0.02 | Feb 11, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet… | ||
| CVE-2024-35279 | Hig | 0.53 | 8.1 | 0.01 | Feb 11, 2025 | A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP control, provided the… |
- risk 0.57cvss 8.8epss 0.02
Windows Telephony Service Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Telephony Service Remote Code Execution Vulnerability
- risk 0.54cvss 8.0epss 0.34
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Office Remote Code Execution Vulnerability
- risk 0.58cvss 7.1epss 0.02
Windows Storage Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Information Disclosure Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.01
DHCP Client Service Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.09
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Telephony Service Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft Digest Authentication Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft Digest Authentication Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Security Feature Bypass Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Core Messaging Elevation of Privileges Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Active Directory Domain Services API Denial of Service Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft PC Manager Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.48cvss 7.3epss 0.01
Visual Studio Installer Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Telephony Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Telephony Service Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.01
Microsoft Surface Security Feature Bypass Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Telephony Service Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Core Messaging Elevation of Privileges Vulnerability
- risk 0.48cvss 7.4epss 0.01
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
- risk 0.48cvss 7.4epss 0.01
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.51cvss 7.8epss 0.00
Illustrator versions 29.1, 28.7.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
- risk 0.51cvss 7.8epss 0.00
Substance3D - Designer versions 14.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…
- risk 0.51cvss 7.8epss 0.00
Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open…
- risk 0.51cvss 7.8epss 0.00
Illustrator versions 29.1, 28.7.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- risk 0.51cvss 7.8epss 0.00
InCopy versions 20.0, 19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.71cvss 8.1epss 0.07
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream…
- risk 0.56cvss 8.6epss 0.01
An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests.
- risk 0.51cvss 7.9epss 0.00
Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Server-side request forgery
- risk 0.51cvss 7.8epss 0.00
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…
- risk 0.51cvss 7.8epss 0.00
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.51cvss 7.8epss 0.00
InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…
- risk 0.47cvss 7.2epss 0.02
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input.
- risk 0.57cvss 8.8epss 0.01
An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to…
- risk 0.47cvss 7.2epss 0.02
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet…
- risk 0.53cvss 8.1epss 0.01
A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP control, provided the…