57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-54092 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-54091 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53801 | HIGH 7.8 | microsoft windows_10_1507 Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53800 | HIGH 7.8 | microsoft windows_10_1607 No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-53789 | HIGH 7.8 | microsoft windows_10_1507 Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53773 | HIGH 7.8 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally. | 2.6% | — |
| CVE-2025-53768 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Xbox allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-53761 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-53759 | HIGH 7.8 | microsoft 365_apps Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-53741 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-53739 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-53738 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-53737 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-53735 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-53734 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-53732 | HIGH 7.8 | microsoft 365_copilot Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-53730 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2025-53729 | HIGH 7.8 | microsoft azure_file_sync Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-53726 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53725 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53724 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53723 | HIGH 7.8 | microsoft windows_10_1507 Numeric truncation error in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-53155 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-53154 | HIGH 7.8 | microsoft windows_10_1507 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53152 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally. | 0.4% | — |