CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-60713

    Last Modified: 26 Feb 2026

    Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    7
    High

    CVE-2025-59515

    Last Modified: 26 Feb 2026

    Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-59514

    Last Modified: 26 Feb 2026

    Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    6.7
    Medium

    CVE-2025-47179

    Last Modified: 26 Feb 2026

    Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    5.5
    Medium

    CVE-2025-59240

    Last Modified: 13 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 11 Nov 2025
    8
    High

    CVE-2025-62452

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

    Published: 11 Nov 2025
    8.8
    High

    CVE-2025-62220

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network.

    Published: 11 Nov 2025
    7
    High

    CVE-2025-62219

    Last Modified: 26 Feb 2026

    Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    7
    High

    CVE-2025-62218

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    7
    High

    CVE-2025-62217

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    6.5
    Medium

    CVE-2025-60722

    Last Modified: 26 Feb 2026

    Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over a network.

    Published: 11 Nov 2025
    7
    High

    CVE-2025-60719

    Last Modified: 26 Feb 2026

    Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-62216

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 11 Nov 2025
    8.7
    High

    CVE-2025-62210

    Last Modified: 26 Feb 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.

    Published: 11 Nov 2025
    6.5
    Medium

    CVE-2025-62206

    Last Modified: 13 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-62199

    Last Modified: 22 May 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 11 Nov 2025
    4.3
    Medium

    CVE-2025-60728

    Last Modified: 13 Feb 2026

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-60727

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 11 Nov 2025
    7.1
    High

    CVE-2025-60726

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-60710

    Last Modified: 22 Apr 2026

    Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-60709

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    6.5
    Medium

    CVE-2025-60708

    Last Modified: 13 Feb 2026

    Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-60707

    Last Modified: 26 Feb 2026

    Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    5.5
    Medium

    CVE-2025-60706

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-60705

    Last Modified: 26 Feb 2026

    Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    7.5
    High

    CVE-2025-60704

    Last Modified: 26 Feb 2026

    Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-60703

    Last Modified: 26 Feb 2026

    Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    5.5
    Medium

    CVE-2025-59513

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-59512

    Last Modified: 26 Feb 2026

    Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-59511

    Last Modified: 26 Feb 2026

    External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    5.5
    Medium

    CVE-2025-59510

    Last Modified: 13 Feb 2026

    Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.

    Published: 11 Nov 2025
    5.5
    Medium

    CVE-2025-59509

    Last Modified: 13 Feb 2026

    Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.

    Published: 11 Nov 2025
    7
    High

    CVE-2025-59508

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    7
    High

    CVE-2025-59507

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    7
    High

    CVE-2025-59506

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-59505

    Last Modified: 26 Feb 2026

    Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.

    Published: 11 Nov 2025
    7.3
    High

    CVE-2025-59504

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61828

    Last Modified: 26 Feb 2026

    Illustrator on iPad versions 3.0.9 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61827

    Last Modified: 26 Feb 2026

    Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61826

    Last Modified: 26 Feb 2026

    Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61829

    Last Modified: 26 Feb 2026

    Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61836

    Last Modified: 26 Feb 2026

    Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61831

    Last Modified: 26 Feb 2026

    Illustrator versions 28.7.10, 29.8.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61820

    Last Modified: 12 Nov 2025

    Illustrator versions 28.7.10, 29.8.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61819

    Last Modified: 26 Feb 2026

    Photoshop Desktop versions 26.8.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61818

    Last Modified: 26 Feb 2026

    InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61816

    Last Modified: 26 Feb 2026

    InCopy versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61817

    Last Modified: 26 Feb 2026

    InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61815

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025
    7.8
    High

    CVE-2025-61814

    Last Modified: 26 Feb 2026

    InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Nov 2025