Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2025-59230 KEV
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.8
CVE-2025-59199
Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7919 / 10.0.19044.6456+
HIGH 7.8
CVE-2025-59201
Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.5
CVE-2025-58726
Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.8
CVE-2025-58724
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Azure Connected Machine Agent
1.57+
HIGH 7.8
CVE-2025-58714
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.8
CVE-2025-55694
Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.6899 / 10.0.26200.6899+
MEDIUM 6.5
CVE-2025-54603
An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of exist…
Mitigation only
HIGH 7.3
CVE-2025-55240
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
Visual Studio 2017
15.9.77 / 16.11.52+
HIGH 7.0
CVE-2025-47989
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Azure Connected Machine Agent
1.57+
MEDIUM 6.5
CVE-2025-37135
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful expl…
Arubaos
8.10.0.19 / 8.12.0.6+
MEDIUM 6.5
CVE-2025-37136
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful expl…
Arubaos
8.10.0.19 / 8.12.0.6+
MEDIUM 6.5
CVE-2025-37137
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful expl…
Arubaos
8.10.0.19 / 8.12.0.6+
HIGH 7.3
CVE-2025-25004
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Powershell
7.4.13 / 7.5.4+
MEDIUM 6.0
CVE-2025-0033
Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially result…
Mitigation only
MEDIUM 6.5
CVE-2025-11716
Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 1…
Firefox
144.0+
CRITICAL 9.8
CVE-2025-27258
Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.
Network Manager
25.1+
CRITICAL 9.8
CVE-2025-11659
A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this vulnerability …
School Management System
Mitigation only
CRITICAL 9.8
CVE-2025-11660
A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this issue…
School Management System
Mitigation only
CRITICAL 9.8
CVE-2025-11658
A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected is an unknown f…
School Management System
Mitigation only
CRITICAL 9.8
CVE-2025-11657
A security vulnerability has been detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This impac…
School Management System
Mitigation only
CRITICAL 9.8
CVE-2025-11656
A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknow…
School Management System
Mitigation only
MEDIUM 6.8
CVE-2025-11647
A flaw has been found in Tomofun Furbo 360 and Furbo Mini. This issue affects some unknown processing of the component GATT Service. This manipulatio…
Furbo Mini Firmware
after 074
HIGH 8.1
CVE-2025-11646
A vulnerability was detected in Tomofun Furbo 360 and Furbo Mini. This vulnerability affects unknown code of the component GATT Service. The manipula…
Furbo Mini Firmware
after 074
MEDIUM 6.4
CVE-2025-11641
A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Trial Restriction Handler. This…
Furbo Mini Firmware
after 074
HIGH 8.7
CVE-2025-62159
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability wa…
Mitigation only
CRITICAL 9.9
CVE-2025-60306
code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sens…
Simple Car Rental System
Mitigation only
HIGH 8.8
CVE-2025-60305
SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low …
Online Student Clearance System
No fix yet
CRITICAL 9.6
CVE-2025-59218
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
HIGH 7.3
CVE-2025-45095
Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCIService.exe service with an unqu…
Mitigation only