VYPR

CVEs

117,426 total · page 527 of 2,349

  • CVE-2025-64679HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-64678HigDec 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-64673HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-64672HigDec 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2025-64671HigDec 9, 2025
    risk 0.55cvss 8.4epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.

  • CVE-2025-64666HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-64661HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2025-64658HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2025-64447HigDec 9, 2025
    risk 0.53cvss 8.1epss 0.08

    A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an unauthenticated attacker…

  • CVE-2025-64156HigDec 9, 2025
    risk 0.47cvss 7.2epss 0.00

    An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7, FortiVoice 6.4 all versions, FortiVoice 6.0 all versions may allow an authenticated privileged…

  • CVE-2025-64153HigDec 9, 2025
    risk 0.47cvss 7.2epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated attacker to…

  • CVE-2025-64086HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.00

    A NULL pointer dereference vulnerability in the util.readFileIntoStream component of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-64085HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.00

    A NULL pointer dereference vulnerability in the importDataObject() function of PDF-XChange Editor v10.7.3.401 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2025-62573HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62572HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62571HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62570HigDec 9, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.

  • CVE-2025-62569HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62565HigDec 9, 2025
    risk 0.47cvss 7.3epss 0.01

    Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62564HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-62563HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-62562HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

  • CVE-2025-62561HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-62560HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-62559HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-62558HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-62557HigDec 9, 2025
    risk 0.55cvss 8.4epss 0.00

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-62556HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-62555HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-62554HigDec 9, 2025
    risk 0.55cvss 8.4epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-62553HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-62552HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.

  • CVE-2025-62550HigDec 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

  • CVE-2025-62549HigDec 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-62474HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62472HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.02

    Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62470HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62469HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62467HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62466HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62464HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62462HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62461HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62458HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62457HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62456HigDec 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.

  • CVE-2025-62455HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62454HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62221HigKEVDec 9, 2025
    risk 0.63cvss 7.8epss 0.03

    Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-61258HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the body length. NOTE: the Supplier indicates that they are unable to reproduce this.