56.950 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.950 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2025-29816 | HIGH 7.5 | microsoft 365_apps Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network. | 0.4% | — |
| CVE-2025-29815 | HIGH 7.6 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-29814 | CRIT 9.3 | microsoft partner_center Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. | 2.2% | — |
| CVE-2025-29813 | CRIT 10.0 | microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | 1.7% | — |
| CVE-2025-29812 | HIGH 7.8 | microsoft windows_11_22h2 Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2025-29811 | HIGH 7.8 | microsoft windows_11_22h2 Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-29810 | HIGH 7.5 | microsoft windows_10_1507 Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. | 2.4% | — |
| CVE-2025-29809 | HIGH 7.1 | microsoft windows_10_1507 Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally. | 4.2% | — |
| CVE-2025-29808 | MED 5.5 | microsoft windows_server_2022 Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-29807 | HIGH 8.7 | microsoft dataverse Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. | 1.3% | — |
| CVE-2025-29806 | MED 6.5 | microsoft edge_chromium No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2025-29805 | HIGH 7.5 | microsoft outlook Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network. | 1.4% | — |
| CVE-2025-29804 | HIGH 7.3 | microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 1.2% | — |
| CVE-2025-29803 | HIGH 7.3 | microsoft sql_server_management_studio Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-29802 | HIGH 7.3 | microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.9% | — |
| CVE-2025-29801 | HIGH 7.8 | microsoft autoupdate Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | 1.0% | — |
| CVE-2025-29800 | HIGH 7.8 | microsoft autoupdate Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | 1.0% | — |
| CVE-2025-29796 | MED 4.7 | microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-29795 | HIGH 7.8 | microsoft edge_update Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-29794 | HIGH 8.8 | microsoft sharepoint_enterprise_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 4.9% | — |
| CVE-2025-29793 | HIGH 7.2 | microsoft sharepoint_enterprise_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 21.6% | — |
| CVE-2025-29792 | HIGH 7.3 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 1.1% | — |
| CVE-2025-29791 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 1.0% | — |
| CVE-2025-2827 | MED 4.3 | ibm sterling_file_gateway IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system. | 0.2% | — |
| CVE-2025-2793 | MED 5.4 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.6, 6.2.0.0 through 6.2.0.4, IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed ar | 0.2% | — |