CVE Feed

    Dashboard / CVE

    7
    High

    CVE-2025-50167

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    6.5
    Medium

    CVE-2025-50166

    Last Modified: 13 Feb 2026

    Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network.

    Published: 12 Aug 2025
    9.8
    Critical

    CVE-2025-50165

    Last Modified: 26 Feb 2026

    Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

    Published: 12 Aug 2025
    8
    High

    CVE-2025-50164

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-50163

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 12 Aug 2025
    8
    High

    CVE-2025-50162

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

    Published: 12 Aug 2025
    7.3
    High

    CVE-2025-50161

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    8
    High

    CVE-2025-50160

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

    Published: 12 Aug 2025
    7.3
    High

    CVE-2025-50159

    Last Modified: 13 Feb 2026

    Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7
    High

    CVE-2025-50158

    Last Modified: 13 Feb 2026

    Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally.

    Published: 12 Aug 2025
    5.7
    Medium

    CVE-2025-50156

    Last Modified: 13 Feb 2026

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

    Published: 12 Aug 2025
    6.5
    Medium

    CVE-2025-50154

    Last Modified: 13 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-50153

    Last Modified: 13 Feb 2026

    Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7
    High

    CVE-2025-49762

    Last Modified: 13 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-49761

    Last Modified: 26 Feb 2026

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-49759

    Last Modified: 13 Feb 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-49757

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 12 Aug 2025
    6.7
    Medium

    CVE-2025-49743

    Last Modified: 13 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    5.3
    Medium

    CVE-2025-25007

    Last Modified: 15 Jun 2026

    Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

    Published: 12 Aug 2025
    5.3
    Medium

    CVE-2025-25006

    Last Modified: 15 Jun 2026

    Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

    Published: 12 Aug 2025
    6.5
    Medium

    CVE-2025-25005

    Last Modified: 15 Jun 2026

    Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

    Published: 12 Aug 2025
    7.7
    High

    CVE-2025-53781

    Last Modified: 13 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53773

    Last Modified: 26 Feb 2026

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-53772

    Last Modified: 26 Feb 2026

    Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-24999

    Last Modified: 26 Feb 2026

    Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53761

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    7.1
    High

    CVE-2025-53760

    Last Modified: 13 Feb 2026

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53759

    Last Modified: 26 Feb 2026

    Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53741

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53730

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

    Published: 12 Aug 2025
    7.5
    High

    CVE-2025-33051

    Last Modified: 15 Jun 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-53729

    Last Modified: 26 Feb 2026

    Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-53727

    Last Modified: 13 Feb 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

    Published: 12 Aug 2025
    8.8
    High

    CVE-2025-49758

    Last Modified: 13 Feb 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

    Published: 12 Aug 2025
    5.4
    Medium

    CVE-2025-49745

    Last Modified: 13 Feb 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network.

    Published: 12 Aug 2025
    6.8
    Medium

    CVE-2025-49751

    Last Modified: 13 Feb 2026

    Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-49563

    Last Modified: 26 Feb 2026

    Illustrator versions 28.7.8, 29.6.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-49568

    Last Modified: 14 Aug 2025

    Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    7.8
    High

    CVE-2025-49564

    Last Modified: 26 Feb 2026

    Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.5
    Medium

    CVE-2025-49567

    Last Modified: 14 Aug 2025

    Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing a disruption in service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 12 Aug 2025
    5.7
    Medium

    CVE-2024-33607

    Last Modified: 31 Aug 2026

    Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 12 Aug 2025
    4.5
    Medium

    CVE-2025-32086

    Last Modified: 15 Apr 2026

    Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 12 Aug 2025
    1.8
    Low

    CVE-2025-32004

    Last Modified: 15 Apr 2026

    Improper input validation in the Intel Edger8r Tool for some Intel(R) SGX SDK may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Aug 2025
    5.4
    Medium

    CVE-2025-27717

    Last Modified: 15 Apr 2026

    Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable escalation of privilege via local access

    Published: 12 Aug 2025
    2.1
    Low

    CVE-2025-27707

    Last Modified: 15 Apr 2026

    Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access.

    Published: 12 Aug 2025
    2.1
    Low

    CVE-2025-27576

    Last Modified: 15 Apr 2026

    Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated user to potentially enable denial of service via local access.

    Published: 12 Aug 2025
    5.4
    Medium

    CVE-2025-27559

    Last Modified: 15 Apr 2026

    Incorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 12 Aug 2025
    5.1
    Medium

    CVE-2025-27537

    Last Modified: 15 Apr 2026

    Improper input validation for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 12 Aug 2025
    5.1
    Medium

    CVE-2025-27250

    Last Modified: 15 Apr 2026

    Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access.

    Published: 12 Aug 2025
    4.8
    Medium

    CVE-2025-26863

    Last Modified: 15 Apr 2026

    Uncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable denial of service.

    Published: 12 Aug 2025