Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-64681

In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations

PUBLISHED
Vendor
JetBrains
Product
Hub
Provider severity
LOW
Conflicts
1

CVE-2025-64680

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 1507, Windows Server 2019, Windows Server 2022, Windows 11 version 22H2, Windows 10 Version 21H2, Windows Server 2019 (Server Core installation), Windows Server 2025, Windows 11 Version 24H2, Windows 11 Version 25H2
Provider severity
HIGH
Conflicts
1

CVE-2025-6468

A vulnerability was found in code-projects Online Bidding System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /bidnow.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Bidding System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-64679

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2025 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 24H2, Windows Server 2022, Windows 11 version 22H2, Windows 11 Version 23H2, Windows Server 2025, Windows 11 version 22H3, Windows 10 Version 21H2, Windows 10 Version 1507, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 10 Version 22H2, Windows 10 Version 1607, Windows 10 Version 1809
Provider severity
HIGH
Conflicts
1

CVE-2025-64678

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 23H2, Windows Server 2016 (Server Core installation), Windows Server 2008 R2 Service Pack 1, Windows Server 2025 (Server Core installation), Windows Server 2012, Windows Server 2012 R2 (Server Core installation), Windows Server 2008 Service Pack 2, Windows 10 Version 21H2, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2012 (Server Core installation), Windows Server 2019, Windows 11 Version 25H2, Windows 11 version 22H3, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2016, Windows Server 2008 Service Pack 2 (Server Core installation), Windows Server 2025, Windows Server 2012 R2, Windows Server 2022, Windows 10 Version 1607, Windows 11 Version 24H2, Windows 10 Version 22H2
Provider severity
HIGH
Conflicts
1

CVE-2025-64677

Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Office Out-of-Box Experience
Provider severity
HIGH
Conflicts
0

CVE-2025-64676

'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft Purview
Provider severity
HIGH
Conflicts
1

CVE-2025-64675

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure Cosmos DB
Provider severity
HIGH
Conflicts
0

CVE-2025-64673

Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 11 Version 24H2, Windows 10 Version 1809, Windows 11 Version 23H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019 (Server Core installation), Windows 11 version 22H3, Windows Server 2022, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 25H2, Windows Server 2025
Provider severity
HIGH
Conflicts
1

CVE-2025-64672

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft SharePoint Server Subscription Edition
Provider severity
HIGH
Conflicts
0

CVE-2025-64671

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.

PUBLISHED
Vendor
Microsoft
Product
GitHub Copilot Plugin for JetBrains IDEs
Provider severity
HIGH
Conflicts
0

CVE-2025-64670

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 21H2, Windows Server 2025, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2022, Windows 11 Version 23H2, Windows 11 Version 25H2, Windows 11 version 22H3
Provider severity
MEDIUM
Conflicts
1

CVE-2025-6467

A vulnerability was found in code-projects Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the file /login.php. The manipulation of the argument User leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Online Bidding System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-64669

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft
Product
Windows Admin Center
Provider severity
HIGH
Conflicts
0

CVE-2025-64667

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server Subscription Edition RTM
Provider severity
MEDIUM
Conflicts
1

CVE-2025-64666

Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft
Product
Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2016 Cumulative Update 23
Provider severity
HIGH
Conflicts
1

CVE-2025-64663

Custom Question Answering Elevation of Privilege Vulnerability

PUBLISHED
Vendor
Microsoft
Product
Azure Cognitive Service for Language
Provider severity
CRITICAL
Conflicts
0

CVE-2025-64661

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 1607, Windows 10 Version 22H2, Windows Server 2016, Windows 10 Version 21H2, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 25H2, Windows Server 2016 (Server Core installation), Windows 11 Version 23H2, Windows 11 Version 24H2, Windows Server 2025 (Server Core installation), Windows 11 version 22H3, Windows Server 2022, Windows Server 2025, Windows Server 2019
Provider severity
HIGH
Conflicts
1

CVE-2025-64660

Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft
Product
Visual Studio Code
Provider severity
HIGH
Conflicts
0

CVE-2025-6466

A vulnerability was found in ageerle ruoyi-ai 2.0.0 and classified as critical. Affected by this issue is the function speechToTextTranscriptionsV2/upload of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/service/impl/SseServiceImpl.java. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.0.1 is able to address this issue. The patch is ide

PUBLISHED
Vendor
ageerle
Product
ruoyi-ai
Provider severity
MEDIUM
Conflicts
2

CVE-2025-64658

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 21H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 1809, Windows Server 2019 (Server Core installation), Windows 11 Version 25H2, Windows Server 2022, 23H2 Edition (Server Core installation), Windows 11 Version 23H2, Windows Server 2019, Windows 11 version 22H3, Windows Server 2025, Windows 10 Version 22H2, Windows Server 2022
Provider severity
HIGH
Conflicts
1

CVE-2025-64657

Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure App Gateway
Provider severity
CRITICAL
Conflicts
0

CVE-2025-64656

Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Azure App Gateway
Provider severity
CRITICAL
Conflicts
0

CVE-2025-64655

Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Dynamics OmniChannel SDK Storage Containers
Provider severity
HIGH
Conflicts
0

CVE-2025-64650

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files.

PUBLISHED
Vendor
IBM
Product
Storage Defender - Resiliency Service
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6465

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names which allows users with file upload permission to overwrite file attachment thumbnails via path traversal in file streaming APIs.

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64648

IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

PUBLISHED
Vendor
IBM
Product
Concert
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64647

IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information

PUBLISHED
Vendor
IBM
Product
Concert
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64646

IBM Concert 1.0.0 through 2.2.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources.

PUBLISHED
Vendor
IBM
Product
Concert
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64645

IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.

PUBLISHED
Vendor
IBM
Product
Concert
Provider severity
HIGH
Conflicts
0

CVE-2025-64642

NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations to modify the program executables and libraries.

PUBLISHED
Vendor
Mirion Medical
Product
EC2 Software NMIS BioDose
Provider severity
HIGH
Conflicts
1

CVE-2025-64641

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted with affected posts

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6464

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.44.2 via deserialization of untrusted input in the 'entry_delete_upload_files' function. This makes it possible for unauthenticated attackers to inject a PHP Object through a PHAR file. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containin

PUBLISHED
Vendor
wpmudev
Product
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Provider severity
HIGH
Conflicts
0

CVE-2025-64639

Missing Authorization vulnerability in WP Compress WP Compress for MainWP wp-compress-mainwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress for MainWP: from n/a through <= 6.50.17.

PUBLISHED
Vendor
WP Compress
Product
WP Compress for MainWP
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64638

Missing Authorization vulnerability in OnPay.io OnPay.io for WooCommerce onpay-io-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OnPay.io for WooCommerce: from n/a through <= 1.0.47.

PUBLISHED
Vendor
OnPay.io
Product
OnPay.io for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64637

Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.

PUBLISHED
Vendor
Opal_WP
Product
Auros Core
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64636

Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.

PUBLISHED
Vendor
rhewlif
Product
Donation Thermometer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64635

Missing Authorization vulnerability in Syed Balkhi Feeds for YouTube feeds-for-youtube allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Feeds for YouTube: from n/a through <= 2.4.0.

PUBLISHED
Vendor
Syed Balkhi
Product
Feeds for YouTube
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64634

Missing Authorization vulnerability in ThemeFusion Avada avada allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Avada: from n/a through <= 7.13.2.

PUBLISHED
Vendor
ThemeFusion
Product
Avada
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64633

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in colabrio Norebro Extra norebro-extra allows Code Injection.This issue affects Norebro Extra: from n/a through <= 1.6.8.

PUBLISHED
Vendor
colabrio
Product
Norebro Extra
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64632

Missing Authorization vulnerability in Auctollo Google XML Sitemaps google-sitemap-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google XML Sitemaps: from n/a through <= 4.1.22.

PUBLISHED
Vendor
Auctollo
Product
Google XML Sitemaps
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64631

Missing Authorization vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marketplace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Marketplace: from n/a through <= 3.7.1.

PUBLISHED
Vendor
WC Lovers
Product
WCFM Marketplace
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64630

Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.19.

PUBLISHED
Vendor
Strategy11 Team
Product
Business Directory
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6463

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function in all versions up to, and including, 1.44.2. This makes it possible for unauthenticated attackers to include arbitrary file paths in a form submission. The file will be deleted when the form submission is deleted, whether by an Administrator or via auto-deletion determined by plu

PUBLISHED
Vendor
wpmudev
Product
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Provider severity
HIGH
Conflicts
0

CVE-2025-64627

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64626

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64623

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64622

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-64620

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

PUBLISHED
Vendor
Adobe
Product
Adobe Experience Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6462

The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SQLREPORT shortcode in all versions up to, and including, 5.25.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
scheeeli
Product
EZ SQL Reports Shortcode Widget and DB Backup
Provider severity
MEDIUM
Conflicts
0