58.061 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.061 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-48805 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-48799 | HIGH 7.8 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. | 1.1% | — |
| CVE-2025-4879 | HIGH 7.8 | citrix workspace Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | 0.1% | — |
| CVE-2025-48000 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-47996 | HIGH 7.8 | microsoft windows_10_1507 Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-47994 | HIGH 7.8 | microsoft 365_apps Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally. | 2.8% | — |
| CVE-2025-47993 | HIGH 7.8 | microsoft windows_11_24h2 Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-47991 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-47987 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. | 1.7% | — |
| CVE-2025-47985 | HIGH 7.8 | microsoft windows_10_1507 Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-47982 | HIGH 7.8 | microsoft windows_10_1607 Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-47976 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-47973 | HIGH 7.8 | microsoft windows_10_1507 Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-47971 | HIGH 7.8 | microsoft windows_10_1507 Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-47968 | HIGH 7.8 | microsoft autoupdate Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-47962 | HIGH 7.8 | microsoft windows_software_development_kit Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally. | 1.6% | — |
| CVE-2025-47955 | HIGH 7.8 | microsoft windows_10_1507 Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 0.9% | — |
| CVE-2025-47761 | HIGH 7.8 | fortinet forticlient An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.9 may allow an authenticated local user to execute unauthorized code via fortips dr | 0.2% | — |
| CVE-2025-47176 | HIGH 7.8 | microsoft 365_apps '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-47175 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | 2.4% | — |
| CVE-2025-47174 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-47173 | HIGH 7.8 | microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-47170 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-47169 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-47168 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |