CVE Feed

    Dashboard / CVE

    7
    High

    CVE-2025-59194

    Last Modified: 22 Feb 2026

    Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-59193

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59192

    Last Modified: 26 Feb 2026

    Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59191

    Last Modified: 22 Feb 2026

    Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-59190

    Last Modified: 22 Feb 2026

    Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.

    Published: 14 Oct 2025
    7.4
    High

    CVE-2025-59189

    Last Modified: 22 Feb 2026

    Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-59188

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59187

    Last Modified: 22 Feb 2026

    Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-59184

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-58739

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-58738

    Last Modified: 26 Feb 2026

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-58737

    Last Modified: 26 Feb 2026

    Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-58736

    Last Modified: 26 Feb 2026

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-58734

    Last Modified: 26 Feb 2026

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-58733

    Last Modified: 26 Feb 2026

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-58731

    Last Modified: 26 Feb 2026

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-58730

    Last Modified: 26 Feb 2026

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-58729

    Last Modified: 22 Feb 2026

    Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-58727

    Last Modified: 22 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.5
    High

    CVE-2025-58726

    Last Modified: 26 Feb 2026

    Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-58725

    Last Modified: 22 Feb 2026

    Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-58724

    Last Modified: 26 Feb 2026

    Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-58720

    Last Modified: 26 Feb 2026

    Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    8.8
    High

    CVE-2025-58718

    Last Modified: 26 Feb 2026

    Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-58714

    Last Modified: 22 Feb 2026

    Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-55699

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    7.7
    High

    CVE-2025-55698

    Last Modified: 22 Feb 2026

    Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-55697

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-55696

    Last Modified: 22 Feb 2026

    Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-55695

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-55694

    Last Modified: 26 Feb 2026

    Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.4
    High

    CVE-2025-55693

    Last Modified: 26 Feb 2026

    Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-55692

    Last Modified: 26 Feb 2026

    Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-55691

    Last Modified: 26 Feb 2026

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-55690

    Last Modified: 26 Feb 2026

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-55688

    Last Modified: 26 Feb 2026

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-55684

    Last Modified: 26 Feb 2026

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-55683

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    6.1
    Medium

    CVE-2025-55682

    Last Modified: 22 Feb 2026

    Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-55680

    Last Modified: 26 Feb 2026

    Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    5.1
    Medium

    CVE-2025-55679

    Last Modified: 22 Feb 2026

    Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-55678

    Last Modified: 26 Feb 2026

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    6.1
    Medium

    CVE-2025-55337

    Last Modified: 22 Feb 2026

    Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

    Published: 14 Oct 2025
    6.2
    Medium

    CVE-2025-55334

    Last Modified: 22 Feb 2026

    Cleartext storage of sensitive information in Windows Kernel allows an unauthorized attacker to bypass a security feature locally.

    Published: 14 Oct 2025
    6.1
    Medium

    CVE-2025-55332

    Last Modified: 22 Feb 2026

    Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-55331

    Last Modified: 26 Feb 2026

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    6.1
    Medium

    CVE-2025-55330

    Last Modified: 22 Feb 2026

    Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-55328

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.5
    High

    CVE-2025-55326

    Last Modified: 26 Feb 2026

    Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.

    Published: 14 Oct 2025
    4.8
    Medium

    CVE-2025-55248

    Last Modified: 22 Feb 2026

    Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

    Published: 14 Oct 2025