VYPR

CVEs

117,419 total · page 550 of 2,349

  • CVE-2025-62200HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-62199HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-61836HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2025-61831HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Illustrator versions 28.7.10, 29.8.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-61829HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-61828HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Illustrator on iPad versions 3.0.9 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-61827HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-61826HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2025-61820HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Illustrator versions 28.7.10, 29.8.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-61819HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Photoshop Desktop versions 26.8.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious…

  • CVE-2025-60727HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-60726HigNov 11, 2025
    risk 0.46cvss 7.1epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2025-60721HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60720HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60719HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.02

    Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60718HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60717HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60716HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60715HigNov 11, 2025
    risk 0.52cvss 8.0epss 0.01

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

  • CVE-2025-60714HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.

  • CVE-2025-60713HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60710HigKEVNov 11, 2025
    risk 0.63cvss 7.8epss 0.05

    Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60709HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60707HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60705HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.02

    Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60704HigNov 11, 2025
    risk 0.49cvss 7.5epss 0.01

    Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-60703HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59515HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59514HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59512HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59511HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59508HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59507HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59506HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59505HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59504HigNov 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

  • CVE-2025-59499HigNov 11, 2025
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-30398HigNov 11, 2025
    risk 0.53cvss 8.1epss 0.01

    Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-61832HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-61824HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-61818HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-61817HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-61816HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InCopy versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-61815HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-61814HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-35971HigNov 11, 2025
    risk 0.53cvss 8.2epss 0.00

    Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial…

  • CVE-2025-35967HigNov 11, 2025
    risk 0.48cvss 7.4epss 0.00

    Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial…

  • CVE-2025-35963HigNov 11, 2025
    risk 0.48cvss 7.4epss 0.00

    Insufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack…

  • CVE-2025-33186HigNov 11, 2025
    risk 0.57cvss 8.8epss 0.00

    NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.

  • CVE-2025-33178HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.00

    NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead to Code execution, Escalation of privileges, Information…