CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-53766CRITICAL | GDI+ Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. CWE-122Aug 12, 2025 | CVSS9.8v3.1 | EPSS7.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53732HIGH | Microsoft Office Remote Code Execution VulnerabilityHeap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS7.8v3.1 | EPSS0.487% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30388HIGH | Windows Graphics Component Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | CVSS7.8v3.1 | EPSS3.65% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-26687HIGH | Win32k Elevation of Privilege VulnerabilityUse after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. CWE-416Apr 8, 2025 | CVSS7.5v3.1 | EPSS1.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-21338HIGH | GDI+ Remote Code Execution VulnerabilityGDI+ Remote Code Execution Vulnerability CWE-190Jan 14, 2025 | CVSS7.8v3.1 | EPSS0.479% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38250HIGH | Windows Graphics Component Elevation of Privilege VulnerabilityWindows Graphics Component Elevation of Privilege Vulnerability CWE-126Sep 10, 2024 | CVSS7.8v3.1 | EPSS0.699% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-36565HIGH | Microsoft Office Graphics Elevation of Privilege VulnerabilityMicrosoft Office Graphics Elevation of Privilege Vulnerability CWE-416Oct 10, 2023 | CVSS7.0v3.1 | EPSS0.417% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-33158HIGH | Microsoft Excel Remote Code Execution VulnerabilityMicrosoft Excel Remote Code Execution Vulnerability CWE-191Jul 11, 2023 | CVSS7.8v3.1 | EPSS0.631% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-24910HIGH | Windows Graphics Component Elevation of Privilege VulnerabilityWindows Graphics Component Elevation of Privilege Vulnerability CWE-476Mar 14, 2023 | CVSS7.8v3.1 | EPSS0.393% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21823HIGH | Windows Graphics Component Remote Code Execution VulnerabilityWindows Graphics Component Remote Code Execution Vulnerability CWE-190Feb 14, 2023 | CVSS7.8v3.1 | EPSS5.56% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |