56.807 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.807 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2025-62559 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-62558 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-62557 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-62556 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-62555 | HIGH 7.0 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-62554 | HIGH 8.4 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-62553 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-62552 | HIGH 7.8 | microsoft 365_apps Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-62550 | HIGH 8.8 | microsoft azure_monitor_agent Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-62549 | HIGH 8.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2025-62503 | MED 4.6 | apache airflow User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action. | 0.4% | — |
| CVE-2025-62474 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62473 | MED 6.5 | microsoft windows_10_1607 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-62472 | HIGH 7.8 | microsoft windows_10_1607 Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 2.2% | — |
| CVE-2025-62470 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-62469 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-62468 | MED 5.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-62467 | HIGH 7.8 | microsoft windows_10_1809 Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62466 | HIGH 7.8 | microsoft windows_10_1607 Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62465 | MED 6.5 | microsoft windows_11_23h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. | 0.5% | — |
| CVE-2025-62464 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62463 | MED 6.5 | microsoft windows_10_21h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. | 0.5% | — |
| CVE-2025-62462 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62461 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-62459 | HIGH 8.3 | microsoft 365_defender_portal Microsoft Defender Portal Spoofing Vulnerability | 0.3% | — |