CVE tracker
312 subscribers
4.46K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-47165 - Microsoft Office Excel Use-After-Free Vulnerability Allows Local Code Execution

CVE ID : CVE-2025-47165
Published : June 10, 2025, 5:23 p.m. | 1 hour, 1 minute ago
Description : Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47166 - Microsoft Office SharePoint Remote Code Execution

CVE ID : CVE-2025-47166
Published : June 10, 2025, 5:23 p.m. | 1 hour, 1 minute ago
Description : Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47167 - Microsoft Office Type Confusion Code Execution

CVE ID : CVE-2025-47167
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47168 - Microsoft Office Word Use-After-Free Remote Code Execution Vulnerability

CVE ID : CVE-2025-47168
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47169 - Microsoft Office Word Heap Buffer Overflow (Code Execution)

CVE ID : CVE-2025-47169
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47170 - Microsoft Office Word Use After Free Code Execution Vulnerability

CVE ID : CVE-2025-47170
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47171 - Microsoft Office Outlook Remote Code Execution Vulnerability

CVE ID : CVE-2025-47171
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47172 - Microsoft Office SharePoint SQL Injection

CVE ID : CVE-2025-47172
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47173 - Microsoft Office Code Execution Vulnerability

CVE ID : CVE-2025-47173
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47174 - Microsoft Office Excel Heap-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-47174
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47175 - Microsoft Office PowerPoint Use After Free Remote Code Execution Vulnerability

CVE ID : CVE-2025-47175
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47176 - Microsoft Office Outlook Code Execution Vulnerability

CVE ID : CVE-2025-47176
Published : June 10, 2025, 5:23 p.m. | 1 hour ago
Description : '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47953 - Microsoft Office Use After Free Remote Code Execution Vulnerability

CVE ID : CVE-2025-47953
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47955 - Microsoft Windows Remote Access Connection Manager Privilege Escalation Vulnerability

CVE ID : CVE-2025-47955
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47956 - Windows Security App Path Traversal Vulnerability

CVE ID : CVE-2025-47956
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47957 - Microsoft Office Word Use-After-Free Remote Code Execution Vulnerability

CVE ID : CVE-2025-47957
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47962 - Windows SDK Privilege Escalation Vulnerability

CVE ID : CVE-2025-47962
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47968 - Microsoft AutoUpdate Privilege Escalation Vulnerability

CVE ID : CVE-2025-47968
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
Severity: 7.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47969 - Windows Hello Information Exposure Vulnerability

CVE ID : CVE-2025-47969
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.
Severity: 4.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-47977 - Nuance Digital Engagement Platform Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-47977
Published : June 10, 2025, 5:24 p.m. | 1 hour ago
Description : Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an authorized attacker to perform spoofing over a network.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-5969 - D-Link DIR-632 HTTP POST Request Handler Stack-Based Buffer Overflow Vulnerability

CVE ID : CVE-2025-5969
Published : June 10, 2025, 5:25 p.m. | 59 minutes ago
Description : A vulnerability has been found in D-Link DIR-632 FW103B08 and classified as critical. Affected by this vulnerability is the function FUN_00425fd8 of the file /biurl_grou of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...