VYPR

CVEs

117,170 total · page 606 of 2,344

  • CVE-2025-54907HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

  • CVE-2025-54906HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-54905HigSep 9, 2025
    risk 0.46cvss 7.1epss 0.01

    Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  • CVE-2025-54904HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54903HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54902HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54900HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54899HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54898HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54897HigSep 9, 2025
    risk 0.59cvss 8.8epss 0.19

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2025-54896HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-54895HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54894HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

  • CVE-2025-54709HigSep 9, 2025
    risk 0.53cvss 8.1epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Sala. This issue affects Sala: from n/a through 1.1.6.

  • CVE-2025-54248HigSep 9, 2025
    risk 0.50cvss 7.7epss 0.05

    Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read…

  • CVE-2025-54116HigSep 9, 2025
    risk 0.47cvss 7.3epss 0.01

    Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54115HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54114HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54113HigSep 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-54112HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54111HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54110HigSep 9, 2025
    risk 0.58cvss 8.8epss 0.04

    Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54108HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54106HigSep 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-54105HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54103HigSep 9, 2025
    risk 0.48cvss 7.4epss 0.00

    Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-54102HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54099HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54098HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54093HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54092HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-54091HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53807HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53805HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.

  • CVE-2025-53802HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53801HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53800HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53303HigSep 9, 2025
    risk 0.57cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object Injection.This issue affects ThemeMove Core: from n/a through <= 1.4.2.

  • CVE-2025-49734HigSep 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49692HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49430HigSep 9, 2025
    risk 0.47cvss 7.2epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request Forgery.This issue affects Ultimate Video Player: from n/a through <= 10.1.

  • CVE-2025-48101HigSep 9, 2025
    risk 0.57cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: from n/a through 4.1.1.

  • CVE-2025-47695HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in solwin Blog Designer PRO blog-designer-pro.This issue affects Blog Designer PRO: from n/a through <= 3.4.7.

  • CVE-2025-47694HigSep 9, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in solwin Blog Designer PRO blog-designer-pro.This issue affects Blog Designer PRO: from n/a through <= 3.4.7.

  • CVE-2025-47571HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder superstorefinder-wp allows PHP Local File Inclusion.This issue affects Super Store Finder: from n/a through < 7.8.

  • CVE-2025-47570HigSep 9, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews.This issue affects WooCommerce Photo Reviews: from n/a through <= 1.3.13.

  • CVE-2025-32689HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects WP SmartPay: from n/a through <= 2.8.2.

  • CVE-2025-9872HigSep 9, 2025
    risk 0.58cvss 8.8epss 0.14

    Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

  • CVE-2025-9712HigSep 9, 2025
    risk 0.59cvss 8.8epss 0.21

    Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

  • CVE-2025-55148HigSep 9, 2025
    risk 0.49cvss 7.6epss 0.01

    Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with…