CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2025-49760

    Last Modified: 13 Feb 2026

    External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.

    Published: 8 Jul 2025
    3.3
    Low

    CVE-2025-49756

    Last Modified: 13 Feb 2026

    Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49753

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 8 Jul 2025
    8
    High

    CVE-2025-47178

    Last Modified: 26 Feb 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network.

    Published: 8 Jul 2025
    8.1
    High

    CVE-2025-49735

    Last Modified: 26 Feb 2026

    Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

    Published: 8 Jul 2025
    3.1
    Low

    CVE-2025-49731

    Last Modified: 26 Feb 2026

    Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49726

    Last Modified: 13 Feb 2026

    Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49723

    Last Modified: 13 Feb 2026

    Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49721

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.5
    High

    CVE-2025-49719

    Last Modified: 13 Feb 2026

    Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.

    Published: 8 Jul 2025
    8.5
    High

    CVE-2025-49717

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

    Published: 8 Jul 2025
    7.5
    High

    CVE-2025-49716

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49711

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-48812

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-47994

    Last Modified: 13 Feb 2026

    Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-47993

    Last Modified: 26 Feb 2026

    Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-47991

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49694

    Last Modified: 13 Feb 2026

    Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    8
    High

    CVE-2025-49691

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.

    Published: 8 Jul 2025
    7.4
    High

    CVE-2025-49690

    Last Modified: 26 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49689

    Last Modified: 26 Feb 2026

    Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49688

    Last Modified: 26 Feb 2026

    Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49687

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49686

    Last Modified: 13 Feb 2026

    Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7
    High

    CVE-2025-49677

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49676

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49674

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49672

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 8 Jul 2025
    6.5
    Medium

    CVE-2025-49671

    Last Modified: 13 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 8 Jul 2025
    6.5
    Medium

    CVE-2025-49670

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-49661

    Last Modified: 26 Feb 2026

    Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-49658

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-49657

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-48824

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-47987

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-53513

    Last Modified: 8 Jan 2026

    The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.

    Published: 8 Jul 2025
    8.8
    High

    CVE-2025-47986

    Last Modified: 26 Feb 2026

    Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-47985

    Last Modified: 26 Feb 2026

    Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.5
    High

    CVE-2025-47984

    Last Modified: 13 Feb 2026

    Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-47976

    Last Modified: 13 Feb 2026

    Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    8
    High

    CVE-2025-47972

    Last Modified: 13 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over a network.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-47971

    Last Modified: 26 Feb 2026

    Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    6
    Medium

    CVE-2025-21195

    Last Modified: 13 Feb 2026

    Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    7.8
    High

    CVE-2025-47159

    Last Modified: 13 Feb 2026

    Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

    Published: 8 Jul 2025
    8.1
    High

    CVE-2025-33054

    Last Modified: 13 Feb 2026

    Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-26636

    Last Modified: 13 Feb 2026

    Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally.

    Published: 8 Jul 2025
    6.5
    Medium

    CVE-2025-53512

    Last Modified: 8 Jan 2026

    The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information.

    Published: 8 Jul 2025
    3.8
    Low

    CVE-2024-36348

    Last Modified: 15 Apr 2026

    A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is enabled, potentially resulting in information leakage.

    Published: 8 Jul 2025
    3.8
    Low

    CVE-2024-36349

    Last Modified: 15 Apr 2026

    A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information leakage.

    Published: 8 Jul 2025
    5.5
    Medium

    CVE-2025-21168

    Last Modified: 11 Jul 2025

    Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 8 Jul 2025