92,816 indexed
CVECVE vulnerabilities
92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 7,051–7,100 of 8,161 in High · page 142 of 164
| ID | Title | Summary |
|---|---|---|
| CVE-2025-21418 | Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a lo… |
| CVE-2025-21417 | CVE-2025-21417 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21416 | CVE-2025-21416 CVSS 8.8 | Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-21415 | CVE-2025-21415 CVSS 8.8 | Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-21413 | CVE-2025-21413 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21411 | CVE-2025-21411 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21410 | CVE-2025-21410 CVSS 8.8 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| CVE-2025-21409 | CVE-2025-21409 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21408 | CVE-2025-21408 CVSS 8.8 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2025-21407 | CVE-2025-21407 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21406 | CVE-2025-21406 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21400 | CVE-2025-21400 CVSS 8.0 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2025-21396 | CVE-2025-21396 CVSS 8.2 | Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-21391 | Microsoft Windows Storage Link Following Vulnerability KEVCVSS 7.1Microsoft | Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to dele… |
| CVE-2025-21384 | CVE-2025-21384 CVSS 8.8 | An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. |
| CVE-2025-21376 | CVE-2025-21376 CVSS 8.1 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
| CVE-2025-21371 | CVE-2025-21371 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21370 | CVE-2025-21370 CVSS 8.8 | Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability |
| CVE-2025-2137 | CVE-2025-2137 CVSS 8.8 | Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chr… |
| CVE-2025-21369 | CVE-2025-21369 CVSS 8.8 | Microsoft Digest Authentication Remote Code Execution Vulnerability |
| CVE-2025-21368 | CVE-2025-21368 CVSS 8.8 | Microsoft Digest Authentication Remote Code Execution Vulnerability |
| CVE-2025-21362 | CVE-2025-21362 CVSS 8.4 | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2025-2136 | CVE-2025-2136 CVSS 8.8 | Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (… |
| CVE-2025-2135 | CVE-2025-2135 CVSS 8.8 | Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… |
| CVE-2025-21342 | CVE-2025-21342 CVSS 8.8 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2025-21339 | CVE-2025-21339 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21335 | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. |
| CVE-2025-21334 | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. |
| CVE-2025-21333 | Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges. |
| CVE-2025-21332 | CVE-2025-21332 CVSS 8.8 | MapUrlToZone Security Feature Bypass Vulnerability |
| CVE-2025-21309 | CVE-2025-21309 CVSS 8.1 | Windows Remote Desktop Services Remote Code Execution Vulnerability |
| CVE-2025-21306 | CVE-2025-21306 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21305 | CVE-2025-21305 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21303 | CVE-2025-21303 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21302 | CVE-2025-21302 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21297 | CVE-2025-21297 CVSS 8.1 | Windows Remote Desktop Services Remote Code Execution Vulnerability |
| CVE-2025-21295 | CVE-2025-21295 CVSS 8.1 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability |
| CVE-2025-21294 | CVE-2025-21294 CVSS 8.1 | Microsoft Digest Authentication Remote Code Execution Vulnerability |
| CVE-2025-21293 | CVE-2025-21293 CVSS 8.8 | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2025-21292 | CVE-2025-21292 CVSS 8.8 | Windows Search Service Elevation of Privilege Vulnerability |
| CVE-2025-21291 | CVE-2025-21291 CVSS 8.8 | Windows Direct Show Remote Code Execution Vulnerability |
| CVE-2025-21286 | CVE-2025-21286 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21283 | CVE-2025-21283 CVSS 8.8 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2025-21282 | CVE-2025-21282 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21279 | CVE-2025-21279 CVSS 8.8 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2025-21273 | CVE-2025-21273 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21266 | CVE-2025-21266 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-2126 | CVE-2025-2126 CVSS 8.8 | A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file /exten… |
| CVE-2025-21252 | CVE-2025-21252 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-21250 | CVE-2025-21250 CVSS 8.8 | Windows Telephony Service Remote Code Execution Vulnerability |