IT
56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.959 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2025-24077 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-24076 HIGH 7.3 microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. 3.2%
CVE-2025-24075 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.7%
CVE-2025-24074 HIGH 7.8 microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-24073 HIGH 7.8 microsoft windows_10_1507 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-24072 HIGH 7.8 microsoft windows_10_1507 Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-24071 MED 6.5 microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. 24.6%
CVE-2025-24070 HIGH 7.0 microsoft asp.net_core Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. 1.0%
CVE-2025-24069 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-24068 MED 5.5 microsoft windows_10_1507 Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-24067 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2025-24066 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2025-24065 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-24064 HIGH 8.1 microsoft windows_server_2008 Use after free in DNS Server allows an unauthorized attacker to execute code over a network. 1.4%
CVE-2025-24063 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2025-24062 HIGH 7.8 microsoft windows_10_21h2 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-24061 HIGH 7.8 microsoft windows_10_1507 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally. 1.2%
CVE-2025-24060 HIGH 7.8 microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-24059 HIGH 7.8 microsoft windows_10_1507 Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-24058 HIGH 7.8 microsoft windows_10_1809 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-24057 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 1.0%
CVE-2025-24056 HIGH 8.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network. 1.7%
CVE-2025-24055 MED 4.3 microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack. 0.9%
CVE-2025-24053 HIGH 7.2 microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2025-24052 HIGH 7.8 microsoft windows_10_1507 Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumula 2.4%