IT
56.950 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.950 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2025-29816 HIGH 7.5 microsoft 365_apps Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network. 0.4%
CVE-2025-29815 HIGH 7.6 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. 0.7%
CVE-2025-29814 CRIT 9.3 microsoft partner_center Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. 2.2%
CVE-2025-29813 CRIT 10.0 microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. 1.7%
CVE-2025-29812 HIGH 7.8 microsoft windows_11_22h2 Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. 0.8%
CVE-2025-29811 HIGH 7.8 microsoft windows_11_22h2 Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-29810 HIGH 7.5 microsoft windows_10_1507 Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. 2.4%
CVE-2025-29809 HIGH 7.1 microsoft windows_10_1507 Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally. 4.2%
CVE-2025-29808 MED 5.5 microsoft windows_server_2022 Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-29807 HIGH 8.7 microsoft dataverse Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. 1.3%
CVE-2025-29806 MED 6.5 microsoft edge_chromium No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2025-29805 HIGH 7.5 microsoft outlook Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network. 1.4%
CVE-2025-29804 HIGH 7.3 microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. 1.2%
CVE-2025-29803 HIGH 7.3 microsoft sql_server_management_studio Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2025-29802 HIGH 7.3 microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. 0.9%
CVE-2025-29801 HIGH 7.8 microsoft autoupdate Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. 1.0%
CVE-2025-29800 HIGH 7.8 microsoft autoupdate Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. 1.0%
CVE-2025-29796 MED 4.7 microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. 0.6%
CVE-2025-29795 HIGH 7.8 microsoft edge_update Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-29794 HIGH 8.8 microsoft sharepoint_enterprise_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 4.9%
CVE-2025-29793 HIGH 7.2 microsoft sharepoint_enterprise_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 21.6%
CVE-2025-29792 HIGH 7.3 microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. 1.1%
CVE-2025-29791 HIGH 7.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 1.0%
CVE-2025-2827 MED 4.3 ibm sterling_file_gateway IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system. 0.2%
CVE-2025-2793 MED 5.4 ibm sterling_b2b_integrator IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed ar 0.2%