CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2025-55240

    Last Modified: 26 Feb 2026

    Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-53768

    Last Modified: 22 Feb 2026

    Use after free in Xbox allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.7
    High

    CVE-2025-53139

    Last Modified: 26 Feb 2026

    Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-50175

    Last Modified: 26 Feb 2026

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-53150

    Last Modified: 26 Feb 2026

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-50152

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-53717

    Last Modified: 26 Feb 2026

    Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.3
    High

    CVE-2025-25004

    Last Modified: 26 Feb 2026

    Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    6.3
    Medium

    CVE-2025-48813

    Last Modified: 26 Feb 2026

    Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.

    Published: 14 Oct 2025
    7.5
    High

    CVE-2025-59502

    Last Modified: 22 Feb 2026

    Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59494

    Last Modified: 26 Feb 2026

    Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    8.8
    High

    CVE-2025-59295

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.

    Published: 14 Oct 2025
    2.1
    Low

    CVE-2025-59294

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.

    Published: 14 Oct 2025
    8.2
    High

    CVE-2025-59292

    Last Modified: 22 Feb 2026

    External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    8.2
    High

    CVE-2025-59291

    Last Modified: 22 Feb 2026

    External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59290

    Last Modified: 22 Feb 2026

    Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    5.3
    Medium

    CVE-2025-59288

    Last Modified: 22 Feb 2026

    Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.

    Published: 14 Oct 2025
    3.3
    Low

    CVE-2025-59284

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-59282

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59281

    Last Modified: 22 Feb 2026

    Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-47979

    Last Modified: 22 Feb 2026

    Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    3.1
    Low

    CVE-2025-59280

    Last Modified: 22 Feb 2026

    Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59277

    Last Modified: 22 Feb 2026

    Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-59259

    Last Modified: 22 Feb 2026

    Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

    Published: 14 Oct 2025
    6.2
    Medium

    CVE-2025-59258

    Last Modified: 22 Feb 2026

    Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-59257

    Last Modified: 22 Feb 2026

    Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59255

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59254

    Last Modified: 22 Feb 2026

    Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    8.1
    High

    CVE-2025-59250

    Last Modified: 26 Feb 2026

    Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.

    Published: 14 Oct 2025
    8.8
    High

    CVE-2025-59249

    Last Modified: 15 Jun 2026

    Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59243

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    9.9
    Critical

    CVE-2025-49708

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59242

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    8.8
    High

    CVE-2025-59237

    Last Modified: 26 Feb 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 14 Oct 2025
    8.4
    High

    CVE-2025-59236

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7.1
    High

    CVE-2025-59235

    Last Modified: 22 Feb 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59234

    Last Modified: 22 May 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59233

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59231

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    8.8
    High

    CVE-2025-59228

    Last Modified: 26 Feb 2026

    Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-59211

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59207

    Last Modified: 26 Feb 2026

    Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.4
    High

    CVE-2025-59206

    Last Modified: 26 Feb 2026

    Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-59204

    Last Modified: 22 Feb 2026

    Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-59202

    Last Modified: 26 Feb 2026

    Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59201

    Last Modified: 26 Feb 2026

    Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.7
    High

    CVE-2025-59200

    Last Modified: 22 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-59199

    Last Modified: 26 Feb 2026

    Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-59196

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-59195

    Last Modified: 22 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.

    Published: 14 Oct 2025