CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2025-59186

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-59185

    Last Modified: 22 Feb 2026

    External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-58735

    Last Modified: 26 Feb 2026

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-58732

    Last Modified: 26 Feb 2026

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-58728

    Last Modified: 26 Feb 2026

    Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-58722

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    4.7
    Medium

    CVE-2025-58719

    Last Modified: 26 Feb 2026

    Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-58717

    Last Modified: 22 Feb 2026

    Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 14 Oct 2025
    4.9
    Medium

    CVE-2025-37143

    Last Modified: 12 Nov 2025

    An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated malicious actor to download arbitrary files through carefully constructed exploits.

    Published: 14 Oct 2025
    8.8
    High

    CVE-2025-58716

    Last Modified: 26 Feb 2026

    Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    8.8
    High

    CVE-2025-58715

    Last Modified: 26 Feb 2026

    Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-55701

    Last Modified: 26 Feb 2026

    Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-55700

    Last Modified: 22 Feb 2026

    Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-55689

    Last Modified: 26 Feb 2026

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.4
    High

    CVE-2025-55687

    Last Modified: 22 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-55686

    Last Modified: 26 Feb 2026

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-55685

    Last Modified: 26 Feb 2026

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-55681

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-55677

    Last Modified: 26 Feb 2026

    Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-55676

    Last Modified: 22 Feb 2026

    Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-55340

    Last Modified: 22 Feb 2026

    Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-55339

    Last Modified: 26 Feb 2026

    Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    6.1
    Medium

    CVE-2025-55338

    Last Modified: 22 Feb 2026

    Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-55336

    Last Modified: 22 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    7.4
    High

    CVE-2025-55335

    Last Modified: 26 Feb 2026

    Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    6.1
    Medium

    CVE-2025-55333

    Last Modified: 22 Feb 2026

    Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

    Published: 14 Oct 2025
    5.5
    Medium

    CVE-2025-55325

    Last Modified: 22 Feb 2026

    Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 14 Oct 2025
    6.8
    Medium

    CVE-2025-55320

    Last Modified: 22 Feb 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-24052

    Last Modified: 26 Feb 2026

    Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific driver will no longer work on Windows. Microsoft recommends removing any existing dependencies on this hardware.

    Published: 14 Oct 2025
    7.8
    High

    CVE-2025-24990

    Last Modified: 26 Feb 2026

    Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific driver will no longer work on Windows. Microsoft recommends removing any existing dependencies on this hardware.

    Published: 14 Oct 2025
    9.9
    Critical

    CVE-2025-55315

    Last Modified: 22 Feb 2026

    Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

    Published: 14 Oct 2025
    7.3
    High

    CVE-2025-55247

    Last Modified: 22 Feb 2026

    Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    8.4
    High

    CVE-2025-53782

    Last Modified: 15 Jun 2026

    Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-50174

    Last Modified: 26 Feb 2026

    Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7.4
    High

    CVE-2025-48004

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    7
    High

    CVE-2025-47989

    Last Modified: 26 Feb 2026

    Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

    Published: 14 Oct 2025
    4.9
    Medium

    CVE-2025-37142

    Last Modified: 12 Nov 2025

    Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.

    Published: 14 Oct 2025
    4.9
    Medium

    CVE-2025-37141

    Last Modified: 12 Nov 2025

    Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.

    Published: 14 Oct 2025
    4.9
    Medium

    CVE-2025-37140

    Last Modified: 12 Nov 2025

    Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.

    Published: 14 Oct 2025
    6
    Medium

    CVE-2025-37139

    Last Modified: 15 Apr 2026

    A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploitation may render the system unbootable, resulting in a Denial of Service that can only be resolved by replacing the affected hardware.

    Published: 14 Oct 2025
    6.2
    Medium

    CVE-2025-37138

    Last Modified: 12 Nov 2025

    An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability requires physical access to the hardware controllers. A successful attack could allow an authenticated malicious actor with physical access to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-37137

    Last Modified: 12 Nov 2025

    Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-37136

    Last Modified: 12 Nov 2025

    Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-37135

    Last Modified: 12 Nov 2025

    Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.

    Published: 14 Oct 2025
    7.2
    High

    CVE-2025-37134

    Last Modified: 26 Feb 2026

    An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 14 Oct 2025
    6.8
    Medium

    CVE-2025-8430

    Last Modified: 22 Oct 2025

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Commands Connectors configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.

    Published: 14 Oct 2025
    7.2
    High

    CVE-2025-37133

    Last Modified: 26 Feb 2026

    An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

    Published: 14 Oct 2025
    7.2
    High

    CVE-2025-37132

    Last Modified: 26 Feb 2026

    An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.

    Published: 14 Oct 2025
    9.3
    Critical

    CVE-2025-11548

    Last Modified: 15 Apr 2026

    A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the application which may lead to unauthenticated Remote Code Execution

    Published: 14 Oct 2025
    6.5
    Medium

    CVE-2025-37148

    Last Modified: 15 Apr 2026

    A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to potentially disrupt network services and require manual intervention to restore functionality.

    Published: 14 Oct 2025