CVE-2025-55240
Last Modified: 26 Feb 2026Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-53768
Last Modified: 22 Feb 2026Use after free in Xbox allows an authorized attacker to elevate privileges locally.
CVE-2025-53139
Last Modified: 26 Feb 2026Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.
CVE-2025-50175
Last Modified: 26 Feb 2026Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-53150
Last Modified: 26 Feb 2026Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-50152
Last Modified: 26 Feb 2026Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-53717
Last Modified: 26 Feb 2026Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
CVE-2025-25004
Last Modified: 26 Feb 2026Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2025-48813
Last Modified: 26 Feb 2026Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
CVE-2025-59502
Last Modified: 22 Feb 2026Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.
CVE-2025-59494
Last Modified: 26 Feb 2026Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-59295
Last Modified: 26 Feb 2026Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
CVE-2025-59294
Last Modified: 22 Feb 2026Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.
CVE-2025-59292
Last Modified: 22 Feb 2026External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
CVE-2025-59291
Last Modified: 22 Feb 2026External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
CVE-2025-59290
Last Modified: 22 Feb 2026Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2025-59288
Last Modified: 22 Feb 2026Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2025-59284
Last Modified: 22 Feb 2026Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
CVE-2025-59282
Last Modified: 26 Feb 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVE-2025-59281
Last Modified: 22 Feb 2026Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
CVE-2025-47979
Last Modified: 22 Feb 2026Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
CVE-2025-59280
Last Modified: 22 Feb 2026Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
CVE-2025-59277
Last Modified: 22 Feb 2026Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
CVE-2025-59259
Last Modified: 22 Feb 2026Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
CVE-2025-59258
Last Modified: 22 Feb 2026Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.
CVE-2025-59257
Last Modified: 22 Feb 2026Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
CVE-2025-59255
Last Modified: 26 Feb 2026Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-59254
Last Modified: 22 Feb 2026Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-59250
Last Modified: 26 Feb 2026Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-59249
Last Modified: 15 Jun 2026Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-59243
Last Modified: 26 Feb 2026Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-49708
Last Modified: 26 Feb 2026Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
CVE-2025-59242
Last Modified: 26 Feb 2026Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2025-59237
Last Modified: 26 Feb 2026Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-59236
Last Modified: 26 Feb 2026Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59235
Last Modified: 22 Feb 2026Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-59234
Last Modified: 22 May 2026Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-59233
Last Modified: 26 Feb 2026Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59231
Last Modified: 26 Feb 2026Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59228
Last Modified: 26 Feb 2026Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-59211
Last Modified: 22 Feb 2026Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
CVE-2025-59207
Last Modified: 26 Feb 2026Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-59206
Last Modified: 26 Feb 2026Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
CVE-2025-59204
Last Modified: 22 Feb 2026Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally.
CVE-2025-59202
Last Modified: 26 Feb 2026Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2025-59201
Last Modified: 26 Feb 2026Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.
CVE-2025-59200
Last Modified: 22 Feb 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally.
CVE-2025-59199
Last Modified: 26 Feb 2026Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.
CVE-2025-59196
Last Modified: 26 Feb 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
CVE-2025-59195
Last Modified: 22 Feb 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.
