IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-49721 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally. 0.5%
CVE-2025-49714 HIGH 7.8 microsoft python Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-49711 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-49705 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-49703 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-49702 HIGH 7.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-49700 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-49698 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-49694 HIGH 7.8 microsoft windows_11_24h2 Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-49693 HIGH 7.8 microsoft windows_11_22h2 Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-49692 HIGH 7.8 microsoft azure_connected_machine_agent Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-49689 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. 0.7%
CVE-2025-49686 HIGH 7.8 microsoft windows_10_1507 Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-49683 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally. 1.9%
CVE-2025-49679 HIGH 7.8 microsoft windows_10_1507 Numeric truncation error in Windows Shell allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-49675 HIGH 7.8 microsoft windows_10_1507 Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-49667 HIGH 7.8 microsoft windows_10_1507 Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-49665 HIGH 7.8 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-49661 HIGH 7.8 microsoft windows_10_1507 Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-49660 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows Event Tracing allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-49659 HIGH 7.8 microsoft windows_10_1507 Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-49570 HIGH 7.8 adobe photoshop Photoshop Desktop versions 25.12.3, 26.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu 0.2%
CVE-2025-49564 HIGH 7.8 adobe illustrator Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim 0.3%
CVE-2025-49563 HIGH 7.8 adobe illustrator Illustrator versions 28.7.8, 29.6.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op 0.2%
CVE-2025-49561 HIGH 7.8 adobe animate Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mali 0.3%