VYPR

CVEs

117,028 total · page 633 of 2,341

  • CVE-2025-53149HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53147HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53145HigAug 12, 2025
    risk 0.58cvss 8.8epss 0.06

    Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

  • CVE-2025-53144HigAug 12, 2025
    risk 0.58cvss 8.8epss 0.06

    Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

  • CVE-2025-53143HigAug 12, 2025
    risk 0.57cvss 8.8epss 0.07

    Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

  • CVE-2025-53142HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53141HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53140HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53137HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53135HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53134HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53133HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53132HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53131HigAug 12, 2025
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

  • CVE-2025-50177HigAug 12, 2025
    risk 0.53cvss 8.1epss 0.04

    Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

  • CVE-2025-50176HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally.

  • CVE-2025-50173HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.01

    Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50170HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50169HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network.

  • CVE-2025-50168HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.01

    Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50167HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50164HigAug 12, 2025
    risk 0.52cvss 8.0epss 0.01

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

  • CVE-2025-50163HigAug 12, 2025
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-50162HigAug 12, 2025
    risk 0.52cvss 8.0epss 0.01

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

  • CVE-2025-50161HigAug 12, 2025
    risk 0.47cvss 7.3epss 0.01

    Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50160HigAug 12, 2025
    risk 0.52cvss 8.0epss 0.01

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

  • CVE-2025-50159HigAug 12, 2025
    risk 0.47cvss 7.3epss 0.01

    Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50158HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally.

  • CVE-2025-50155HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

  • CVE-2025-50153HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49762HigAug 12, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49761HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49759HigAug 12, 2025
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-49758HigAug 12, 2025
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-49757HigAug 12, 2025
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-49712HigAug 12, 2025
    risk 0.59cvss 8.8epss 0.20

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2025-49707HigAug 12, 2025
    risk 0.51cvss 7.9epss 0.00

    Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.

  • CVE-2025-49557HigAug 12, 2025
    risk 0.57cvss 8.7epss 0.01

    Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be exploited by a low-privileged attacker to inject malicious scripts into vulnerable form fields. A…

  • CVE-2025-49556HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass security…

  • CVE-2025-49555HigAug 12, 2025
    risk 0.53cvss 8.1epss 0.01

    Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege escalation. A high-privileged attacker could trick a victim into executing…

  • CVE-2025-49554HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially…

  • CVE-2025-47954HigAug 12, 2025
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-33051HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-24999HigAug 12, 2025
    risk 0.57cvss 8.8epss 0.02

    Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-49564HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2025-49563HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Illustrator versions 28.7.8, 29.6.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2025-32086HigAug 12, 2025
    risk 0.47cvss 7.2epss 0.00

    Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2025-26403HigAug 12, 2025
    risk 0.47cvss 7.2epss 0.00

    Out-of-bounds write in the memory subsystem for some Intel(R) Xeon(R) 6 processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2025-25273HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Insufficient control flow management in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-24486HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable escalation of privilege via local access.