Search

Search Results (314586 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-59238 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2025-10-16 7.8 High
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-59243 1 Microsoft 2 365 Apps, Office Long Term Servicing Channel 2025-10-16 7.8 High
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59221 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2025-10-16 7 High
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-59222 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2025-10-16 7.8 High
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-59232 1 Microsoft 7 365 Apps, Access, Excel and 4 more 2025-10-16 7.1 High
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-59235 1 Microsoft 7 365 Apps, Access, Excel and 4 more 2025-10-16 7.1 High
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-59218 1 Microsoft 1 Entra Id 2025-10-16 9.6 Critical
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-59246 1 Microsoft 1 Entra Id 2025-10-16 9.8 Critical
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-46546 1 Sherparpa 1 Sherpa Orchestrator 2025-10-16 3.5 Low
In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, /api/gui/processVersion/export/xlsx/, /api/gui/processVersion/list/, /api/gui/robot/list/, /api/gui/task/export/csv/, /api/gui/task/export/xlsx/, and /api/gui/task/list/.
CVE-2025-46547 1 Sherparpa 1 Sherpa Orchestrator 2025-10-16 5.4 Medium
In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.
CVE-2025-46653 1 Node-formidable 1 Formidable 2025-10-16 3.1 Low
Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.
CVE-2025-46656 1 Matthewwithanm 1 Markdownify 2025-10-16 2.9 Low
python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.
CVE-2025-10035 1 Fortra 1 Goanywhere Managed File Transfer 2025-10-16 10 Critical
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.
CVE-2025-50175 1 Microsoft 11 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 8 more 2025-10-16 7.8 High
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-59223 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-10-16 7.8 High
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59224 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-10-16 7.8 High
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59225 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-10-16 7.8 High
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59226 1 Microsoft 2 365 Apps, Office Long Term Servicing Channel 2025-10-16 7.8 High
Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
CVE-2025-59227 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-10-16 7.8 High
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-62412 2025-10-16 3.8 Low
LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitized, and can be used to inject HTML code. This vulnerability is fixed in 25.10.0.