58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-58720 | HIGH 7.8 | microsoft windows_10_1809 Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | 0.2% | — |
| CVE-2025-58714 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-58097 | HIGH 7.8 | secuavail logstare_collector The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege. | 0.1% | — |
| CVE-2025-57836 | HIGH 7.8 | samsung magician An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL hijacking and escalate privileges. | 0.1% | — |
| CVE-2025-57741 | HIGH 7.8 | fortinet forticlient An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local attacker to run arbitrary code or commands via LaunchDaemon hijacking. | 0.1% | — |
| CVE-2025-55701 | HIGH 7.8 | microsoft windows_10_1507 Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55697 | HIGH 7.8 | microsoft windows_server_2022_23h2 Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55696 | HIGH 7.8 | microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-55694 | HIGH 7.8 | microsoft windows_11_24h2 Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | 3.0% | — |
| CVE-2025-55692 | HIGH 7.8 | microsoft windows_10_1507 Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | 3.4% | — |
| CVE-2025-55680 | HIGH 7.8 | microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55677 | HIGH 7.8 | microsoft windows_11_24h2 Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55339 | HIGH 7.8 | microsoft windows_11_22h2 Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55328 | HIGH 7.8 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-55317 | HIGH 7.8 | microsoft autoupdate Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55316 | HIGH 7.8 | microsoft azure_connected_machine_agent External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55314 | HIGH 7.8 | foxit pdf_editor An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations a | 0.2% | — |
| CVE-2025-55313 | HIGH 7.8 | foxit pdf_editor An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling of memory allocation f | 0.2% | — |
| CVE-2025-55312 | HIGH 7.8 | foxit pdf_editor An issue was discovered in Foxit PDF and Editor for Windows before 13.2 and 2025 before 2025.2. When pages in a PDF are deleted via JavaScript, the application may fail to properly update internal states. Subsequent annotation management operations assume thes | 0.2% | — |
| CVE-2025-55245 | HIGH 7.8 | microsoft xbox_gaming_services Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55233 | HIGH 7.8 | microsoft windows_10_1809 Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55230 | HIGH 7.8 | microsoft windows_10_1507 Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-55228 | HIGH 7.8 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2025-55224 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | 0.3% | — |
| CVE-2025-54916 | HIGH 7.8 | microsoft windows_10_1507 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 2.3% | — |