VYPR

CVEs

117,354 total · page 576 of 2,348

  • CVE-2025-58722HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.02

    Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2025-58720HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

  • CVE-2025-58718HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.01

    Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2025-58716HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

  • CVE-2025-58715HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.00

    Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

  • CVE-2025-58714HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55701HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55698HigOct 14, 2025
    risk 0.50cvss 7.7epss 0.01

    Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network.

  • CVE-2025-55697HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55696HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55694HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55693HigOct 14, 2025
    risk 0.48cvss 7.4epss 0.02

    Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-55692HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55691HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55690HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55689HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55688HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55687HigOct 14, 2025
    risk 0.48cvss 7.4epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-55686HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55685HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55684HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55681HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.05

    Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55680HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55678HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55677HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55340HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.

  • CVE-2025-55339HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55335HigOct 14, 2025
    risk 0.48cvss 7.4epss 0.00

    Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-55331HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55328HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55326HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-55247HigOct 14, 2025
    risk 0.47cvss 7.3epss 0.01

    Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55240HigOct 14, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53782HigOct 14, 2025
    risk 0.55cvss 8.4epss 0.00

    Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-53768HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Xbox allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53717HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53150HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53139HigOct 14, 2025
    risk 0.50cvss 7.7epss 0.00

    Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2025-50175HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50174HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50152HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-48004HigOct 14, 2025
    risk 0.48cvss 7.4epss 0.02

    Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-47989HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.01

    Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2025-37147HigOct 14, 2025
    risk 0.46cvss 7.1epss 0.00

    A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exploit this vulnerability to run modified or…

  • CVE-2025-37146HigOct 14, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to perform remote command execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying…

  • CVE-2025-37134HigOct 14, 2025
    risk 0.47cvss 7.2epss 0.01

    An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying…

  • CVE-2025-37133HigOct 14, 2025
    risk 0.47cvss 7.2epss 0.01

    An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying…

  • CVE-2025-37132HigOct 14, 2025
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute…

  • CVE-2025-25004HigOct 14, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24990HigKEVOct 14, 2025
    risk 0.63cvss 7.8epss 0.06

    Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax…