Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 32214 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-21273 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-01-27 N/A 8.8 HIGH
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21274 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-01-27 N/A 5.5 MEDIUM
Windows Event Tracing Denial of Service Vulnerability
CVE-2025-21275 1 Microsoft 8 Windows 10 21h2, Windows 10 22h2, Windows 11 22h2 and 5 more 2025-01-27 N/A 7.8 HIGH
Windows App Package Installer Elevation of Privilege Vulnerability
CVE-2025-21276 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-01-27 N/A 7.5 HIGH
Windows MapUrlToZone Denial of Service Vulnerability
CVE-2025-21277 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-01-27 N/A 7.5 HIGH
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2025-21278 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-01-27 N/A 6.2 MEDIUM
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
CVE-2025-21280 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-01-27 N/A 5.5 MEDIUM
Windows Virtual Trusted Platform Module Denial of Service Vulnerability
CVE-2025-21281 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2025-01-27 N/A 7.8 HIGH
Microsoft COM for Windows Elevation of Privilege Vulnerability
CVE-2025-21282 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2025-01-27 N/A 8.8 HIGH
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21284 1 Microsoft 13 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 10 more 2025-01-27 N/A 5.5 MEDIUM
Windows Virtual Trusted Platform Module Denial of Service Vulnerability
CVE-2025-21314 1 Microsoft 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more 2025-01-27 N/A 6.5 MEDIUM
Windows SmartScreen Spoofing Vulnerability
CVE-2025-21402 1 Microsoft 2 Office, Onenote 2025-01-27 N/A 7.8 HIGH
Microsoft Office OneNote Remote Code Execution Vulnerability
CVE-2025-21403 1 Microsoft 1 On-prem Data Gateway 2025-01-27 N/A 6.4 MEDIUM
On-Premises Data Gateway Information Disclosure Vulnerability
CVE-2024-30258 1 Eprosima 1 Fast Dds 2025-01-27 N/A 8.2 HIGH
FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves a malformed `RTPS` packet, the subscriber crashes when creating `pthread`. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8 contain a patch for the issue.
CVE-2023-42929 1 Apple 1 Macos 2025-01-27 N/A 5.5 MEDIUM
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access protected user data.
CVE-2023-20880 1 Vmware 2 Aria Operations, Cloud Foundation 2025-01-27 N/A 6.7 MEDIUM
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
CVE-2023-20877 1 Vmware 2 Cloud Foundation, Vrealize Operations 2025-01-27 N/A 8.8 HIGH
VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.
CVE-2024-35171 1 Kodezen 1 Academy Lms 2025-01-27 N/A 5.3 MEDIUM
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.25.
CVE-2024-28226 1 Openatom 1 Openharmony 2025-01-27 N/A 8.1 HIGH
in OpenHarmony v4.0.0 and prior versions allow a remote attacker cause DOS through improper input.
CVE-2024-0616 1 Wpchill 1 Passster 2025-01-27 N/A 5.3 MEDIUM
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles, slugs, IDs, content and other metadata including passwords of password-protected posts and pages.