CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-54912

    Last Modified: 20 Feb 2026

    Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.3
    High

    CVE-2025-54911

    Last Modified: 20 Feb 2026

    Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    8.4
    High

    CVE-2025-54910

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 9 Sept 2025
    5.5
    Medium

    CVE-2025-54901

    Last Modified: 20 Feb 2026

    Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54900

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 9 Sept 2025
    7.3
    High

    CVE-2025-54116

    Last Modified: 20 Feb 2026

    Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7
    High

    CVE-2025-54115

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7
    High

    CVE-2025-54114

    Last Modified: 20 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    8.8
    High

    CVE-2025-54113

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 9 Sept 2025
    7
    High

    CVE-2025-54112

    Last Modified: 20 Feb 2026

    Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    6.7
    Medium

    CVE-2025-54109

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7
    High

    CVE-2025-54108

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    4.3
    Medium

    CVE-2025-54107

    Last Modified: 20 Feb 2026

    Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

    Published: 9 Sept 2025
    7
    High

    CVE-2025-54105

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    6.7
    Medium

    CVE-2025-54104

    Last Modified: 20 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.4
    High

    CVE-2025-54103

    Last Modified: 20 Feb 2026

    Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54098

    Last Modified: 26 Feb 2026

    Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    6.7
    Medium

    CVE-2025-54094

    Last Modified: 20 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7
    High

    CVE-2025-54093

    Last Modified: 26 Feb 2026

    Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54092

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54091

    Last Modified: 20 Feb 2026

    Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    6.7
    Medium

    CVE-2025-53810

    Last Modified: 20 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-53809

    Last Modified: 20 Feb 2026

    Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

    Published: 9 Sept 2025
    6.7
    Medium

    CVE-2025-53808

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7
    High

    CVE-2025-53807

    Last Modified: 20 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-53806

    Last Modified: 20 Feb 2026

    Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 9 Sept 2025
    7.5
    High

    CVE-2025-53805

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.

    Published: 9 Sept 2025
    5.5
    Medium

    CVE-2025-53804

    Last Modified: 20 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

    Published: 9 Sept 2025
    5.5
    Medium

    CVE-2025-53803

    Last Modified: 20 Feb 2026

    Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

    Published: 9 Sept 2025
    7
    High

    CVE-2025-53802

    Last Modified: 26 Feb 2026

    Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-53801

    Last Modified: 20 Feb 2026

    Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-53800

    Last Modified: 26 Feb 2026

    No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    5.5
    Medium

    CVE-2025-53799

    Last Modified: 22 May 2026

    Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-53796

    Last Modified: 20 Feb 2026

    Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-47997

    Last Modified: 20 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-49692

    Last Modified: 26 Feb 2026

    Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-55317

    Last Modified: 26 Feb 2026

    Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-55316

    Last Modified: 26 Feb 2026

    External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.5
    High

    CVE-2025-55243

    Last Modified: 20 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-55245

    Last Modified: 26 Feb 2026

    Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.3
    High

    CVE-2025-55236

    Last Modified: 20 Feb 2026

    Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally.

    Published: 9 Sept 2025
    9.8
    Critical

    CVE-2025-55232

    Last Modified: 20 Feb 2026

    Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-55228

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

    Published: 9 Sept 2025
    6.7
    Medium

    CVE-2025-55226

    Last Modified: 20 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally.

    Published: 9 Sept 2025
    6.5
    Medium

    CVE-2025-55225

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 9 Sept 2025
    7
    High

    CVE-2025-55223

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025
    7.5
    High

    CVE-2025-54919

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

    Published: 9 Sept 2025
    8.8
    High

    CVE-2025-54918

    Last Modified: 20 Feb 2026

    Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54916

    Last Modified: 20 Feb 2026

    Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

    Published: 9 Sept 2025
    7.8
    High

    CVE-2025-54913

    Last Modified: 20 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally.

    Published: 9 Sept 2025