CVE-2025-49760
Last Modified: 13 Feb 2026External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.
CVE-2025-49756
Last Modified: 13 Feb 2026Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally.
CVE-2025-49753
Last Modified: 26 Feb 2026Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-47178
Last Modified: 26 Feb 2026Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network.
CVE-2025-49735
Last Modified: 26 Feb 2026Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
CVE-2025-49731
Last Modified: 26 Feb 2026Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2025-49726
Last Modified: 13 Feb 2026Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
CVE-2025-49723
Last Modified: 13 Feb 2026Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.
CVE-2025-49721
Last Modified: 13 Feb 2026Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
CVE-2025-49719
Last Modified: 13 Feb 2026Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
CVE-2025-49717
Last Modified: 26 Feb 2026Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2025-49716
Last Modified: 13 Feb 2026Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
CVE-2025-49711
Last Modified: 13 Feb 2026Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-48812
Last Modified: 13 Feb 2026Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-47994
Last Modified: 13 Feb 2026Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
CVE-2025-47993
Last Modified: 26 Feb 2026Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
CVE-2025-47991
Last Modified: 13 Feb 2026Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
CVE-2025-49694
Last Modified: 13 Feb 2026Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2025-49691
Last Modified: 13 Feb 2026Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.
CVE-2025-49690
Last Modified: 26 Feb 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.
CVE-2025-49689
Last Modified: 26 Feb 2026Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
CVE-2025-49688
Last Modified: 26 Feb 2026Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-49687
Last Modified: 13 Feb 2026Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
CVE-2025-49686
Last Modified: 13 Feb 2026Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2025-49677
Last Modified: 13 Feb 2026Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2025-49676
Last Modified: 26 Feb 2026Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-49674
Last Modified: 13 Feb 2026Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-49672
Last Modified: 26 Feb 2026Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-49671
Last Modified: 13 Feb 2026Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-49670
Last Modified: 26 Feb 2026Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-49661
Last Modified: 26 Feb 2026Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2025-49658
Last Modified: 13 Feb 2026Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.
CVE-2025-49657
Last Modified: 26 Feb 2026Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-48824
Last Modified: 26 Feb 2026Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-47987
Last Modified: 13 Feb 2026Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.
CVE-2025-53513
Last Modified: 8 Jan 2026The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.
CVE-2025-47986
Last Modified: 26 Feb 2026Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
CVE-2025-47985
Last Modified: 26 Feb 2026Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
CVE-2025-47984
Last Modified: 13 Feb 2026Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.
CVE-2025-47976
Last Modified: 13 Feb 2026Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
CVE-2025-47972
Last Modified: 13 Feb 2026Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over a network.
CVE-2025-47971
Last Modified: 26 Feb 2026Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
CVE-2025-21195
Last Modified: 13 Feb 2026Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.
CVE-2025-47159
Last Modified: 13 Feb 2026Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
CVE-2025-33054
Last Modified: 13 Feb 2026Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-26636
Last Modified: 13 Feb 2026Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2025-53512
Last Modified: 8 Jan 2026The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information.
CVE-2024-36348
Last Modified: 15 Apr 2026A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is enabled, potentially resulting in information leakage.
CVE-2024-36349
Last Modified: 15 Apr 2026A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information leakage.
CVE-2025-21168
Last Modified: 11 Jul 2025Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
