CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-53737

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    6.8
    Medium

    CVE-2025-53736

    Last Modified: 13 Feb 2026

    Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53735

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53734

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    8.4
    High

    CVE-2025-53733

    Last Modified: 13 Feb 2026

    Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53732

    Last Modified: 22 May 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    8.4
    High

    CVE-2025-53731

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-47954

    Last Modified: 26 Feb 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

    Published: 12 Aug 2025
    6.5
    Medium

    CVE-2025-53728

    Last Modified: 13 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53726

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53725

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53724

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53723

    Last Modified: 26 Feb 2026

    Numeric truncation error in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7.5
    High

    CVE-2025-53722

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network.

    Published: 12 Aug 2025
    7
    High

    CVE-2025-53721

    Last Modified: 13 Feb 2026

    Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    8
    High

    CVE-2025-53720

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

    Published: 12 Aug 2025
    5.7
    Medium

    CVE-2025-53719

    Last Modified: 13 Feb 2026

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

    Published: 12 Aug 2025
    7
    High

    CVE-2025-53718

    Last Modified: 13 Feb 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    6.5
    Medium

    CVE-2025-53716

    Last Modified: 13 Feb 2026

    Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-53156

    Last Modified: 13 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53155

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53154

    Last Modified: 13 Feb 2026

    Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    5.7
    Medium

    CVE-2025-53153

    Last Modified: 13 Feb 2026

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53152

    Last Modified: 13 Feb 2026

    Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53151

    Last Modified: 26 Feb 2026

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53149

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    5.7
    Medium

    CVE-2025-53148

    Last Modified: 13 Feb 2026

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

    Published: 12 Aug 2025
    7
    High

    CVE-2025-53147

    Last Modified: 13 Feb 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-53145

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-53144

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-53143

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

    Published: 12 Aug 2025
    7
    High

    CVE-2025-53142

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53141

    Last Modified: 13 Feb 2026

    Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7
    High

    CVE-2025-53140

    Last Modified: 26 Feb 2026

    Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    5.7
    Medium

    CVE-2025-53138

    Last Modified: 13 Feb 2026

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

    Published: 12 Aug 2025
    7
    High

    CVE-2025-53137

    Last Modified: 13 Feb 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-53136

    Last Modified: 13 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disclose information locally.

    Published: 12 Aug 2025
    7
    High

    CVE-2025-53135

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7
    High

    CVE-2025-53134

    Last Modified: 13 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53133

    Last Modified: 26 Feb 2026

    Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53132

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-53131

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

    Published: 12 Aug 2025
    8.1
    High

    CVE-2025-50177

    Last Modified: 26 Feb 2026

    Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-50176

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-50173

    Last Modified: 26 Feb 2026

    Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    6.5
    Medium

    CVE-2025-50172

    Last Modified: 13 Feb 2026

    Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network.

    Published: 12 Aug 2025
    9.1
    Critical

    CVE-2025-50171

    Last Modified: 13 Feb 2026

    Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-50170

    Last Modified: 13 Feb 2026

    Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7.5
    High

    CVE-2025-50169

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-50168

    Last Modified: 26 Feb 2026

    Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025