CVE tracker
311 subscribers
4.45K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-49511 - Civi Framework CSRF

CVE ID : CVE-2025-49511
Published : June 10, 2025, 1:15 p.m. | 1 hour, 3 minutes ago
Description : Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework allows Cross Site Request Forgery.This issue affects Civi Framework: from n/a through 2.1.6.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47162 - Microsoft Office Heap-based Buffer Overflow Vulnerability

CVE ID : CVE-2025-47162
Published : June 10, 2025, 5:23 p.m. | 1 hour, 1 minute ago
Description : Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47163 - Microsoft Office SharePoint Remote Code Execution Vulnerability

CVE ID : CVE-2025-47163
Published : June 10, 2025, 5:23 p.m. | 1 hour, 1 minute ago
Description : Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47164 - Microsoft Office Use After Free Remote Code Execution Vulnerability

CVE ID : CVE-2025-47164
Published : June 10, 2025, 5:23 p.m. | 1 hour, 1 minute ago
Description : Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47165 - Microsoft Office Excel Use-After-Free Vulnerability Allows Local Code Execution

CVE ID : CVE-2025-47165
Published : June 10, 2025, 5:23 p.m. | 1 hour, 1 minute ago
Description : Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47166 - Microsoft Office SharePoint Remote Code Execution

CVE ID : CVE-2025-47166
Published : June 10, 2025, 5:23 p.m. | 1 hour, 1 minute ago
Description : Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47167 - Microsoft Office Type Confusion Code Execution

CVE ID : CVE-2025-47167
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47168 - Microsoft Office Word Use-After-Free Remote Code Execution Vulnerability

CVE ID : CVE-2025-47168
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47169 - Microsoft Office Word Heap Buffer Overflow (Code Execution)

CVE ID : CVE-2025-47169
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47170 - Microsoft Office Word Use After Free Code Execution Vulnerability

CVE ID : CVE-2025-47170
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47171 - Microsoft Office Outlook Remote Code Execution Vulnerability

CVE ID : CVE-2025-47171
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47172 - Microsoft Office SharePoint SQL Injection

CVE ID : CVE-2025-47172
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47173 - Microsoft Office Code Execution Vulnerability

CVE ID : CVE-2025-47173
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47174 - Microsoft Office Excel Heap-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-47174
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47175 - Microsoft Office PowerPoint Use After Free Remote Code Execution Vulnerability

CVE ID : CVE-2025-47175
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47176 - Microsoft Office Outlook Code Execution Vulnerability

CVE ID : CVE-2025-47176
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47953 - Microsoft Office Use After Free Remote Code Execution Vulnerability

CVE ID : CVE-2025-47953
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47955 - Microsoft Windows Remote Access Connection Manager Privilege Escalation Vulnerability

CVE ID : CVE-2025-47955
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47956 - Windows Security App Path Traversal Vulnerability

CVE ID : CVE-2025-47956
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47957 - Microsoft Office Word Use-After-Free Remote Code Execution Vulnerability

CVE ID : CVE-2025-47957
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47962 - Windows SDK Privilege Escalation Vulnerability

CVE ID : CVE-2025-47962
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...