92,816 indexed

CVECVE vulnerabilities

92,816 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 7,051–7,100 of 8,161 in High · page 142 of 164

IDTitleSummary
CVE-2025-21418Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a lo…
CVE-2025-21417CVE-2025-21417
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21416CVE-2025-21416
CVSS 8.8
Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.
CVE-2025-21415CVE-2025-21415
CVSS 8.8
Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.
CVE-2025-21413CVE-2025-21413
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21411CVE-2025-21411
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21410CVE-2025-21410
CVSS 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-21409CVE-2025-21409
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21408CVE-2025-21408
CVSS 8.8
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-21407CVE-2025-21407
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21406CVE-2025-21406
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21400CVE-2025-21400
CVSS 8.0
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2025-21396CVE-2025-21396
CVSS 8.2
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-21391Microsoft Windows Storage Link Following Vulnerability
KEVCVSS 7.1Microsoft
Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to dele…
CVE-2025-21384CVE-2025-21384
CVSS 8.8
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.
CVE-2025-21376CVE-2025-21376
CVSS 8.1
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2025-21371CVE-2025-21371
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21370CVE-2025-21370
CVSS 8.8
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
CVE-2025-2137CVE-2025-2137
CVSS 8.8
Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chr…
CVE-2025-21369CVE-2025-21369
CVSS 8.8
Microsoft Digest Authentication Remote Code Execution Vulnerability
CVE-2025-21368CVE-2025-21368
CVSS 8.8
Microsoft Digest Authentication Remote Code Execution Vulnerability
CVE-2025-21362CVE-2025-21362
CVSS 8.4
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-2136CVE-2025-2136
CVSS 8.8
Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (…
CVE-2025-2135CVE-2025-2135
CVSS 8.8
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…
CVE-2025-21342CVE-2025-21342
CVSS 8.8
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-21339CVE-2025-21339
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21335Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21334Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21333Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21332CVE-2025-21332
CVSS 8.8
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-21309CVE-2025-21309
CVSS 8.1
Windows Remote Desktop Services Remote Code Execution Vulnerability
CVE-2025-21306CVE-2025-21306
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21305CVE-2025-21305
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21303CVE-2025-21303
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21302CVE-2025-21302
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21297CVE-2025-21297
CVSS 8.1
Windows Remote Desktop Services Remote Code Execution Vulnerability
CVE-2025-21295CVE-2025-21295
CVSS 8.1
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
CVE-2025-21294CVE-2025-21294
CVSS 8.1
Microsoft Digest Authentication Remote Code Execution Vulnerability
CVE-2025-21293CVE-2025-21293
CVSS 8.8
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2025-21292CVE-2025-21292
CVSS 8.8
Windows Search Service Elevation of Privilege Vulnerability
CVE-2025-21291CVE-2025-21291
CVSS 8.8
Windows Direct Show Remote Code Execution Vulnerability
CVE-2025-21286CVE-2025-21286
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21283CVE-2025-21283
CVSS 8.8
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-21282CVE-2025-21282
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21279CVE-2025-21279
CVSS 8.8
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-21273CVE-2025-21273
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21266CVE-2025-21266
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-2126CVE-2025-2126
CVSS 8.8
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file /exten…
CVE-2025-21252CVE-2025-21252
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21250CVE-2025-21250
CVSS 8.8
Windows Telephony Service Remote Code Execution Vulnerability
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.