CVE-2025-47977
Last Modified: 20 Feb 2026Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-47968
Last Modified: 26 Feb 2026Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
CVE-2025-47176
Last Modified: 26 Feb 2026'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
CVE-2025-47175
Last Modified: 26 Feb 2026Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-47174
Last Modified: 20 Feb 2026Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-47173
Last Modified: 26 Feb 2026Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47172
Last Modified: 26 Feb 2026Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-47171
Last Modified: 26 Feb 2026Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
CVE-2025-47170
Last Modified: 26 Feb 2026Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47169
Last Modified: 26 Feb 2026Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47168
Last Modified: 26 Feb 2026Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47167
Last Modified: 22 May 2026Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47166
Last Modified: 26 Feb 2026Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-47165
Last Modified: 26 Feb 2026Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-47164
Last Modified: 22 May 2026Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47163
Last Modified: 26 Feb 2026Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-33073
Last Modified: 26 Feb 2026Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
CVE-2025-33070
Last Modified: 26 Feb 2026Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-33069
Last Modified: 20 Feb 2026Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.
CVE-2025-33068
Last Modified: 20 Feb 2026Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
CVE-2025-33057
Last Modified: 20 Feb 2026Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.
CVE-2025-33056
Last Modified: 20 Feb 2026Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.
CVE-2025-33055
Last Modified: 20 Feb 2026Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33053
Last Modified: 26 Feb 2026External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
CVE-2025-33052
Last Modified: 20 Feb 2026Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2025-33050
Last Modified: 20 Feb 2026Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2025-32725
Last Modified: 20 Feb 2026Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2025-24065
Last Modified: 20 Feb 2026Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-24069
Last Modified: 20 Feb 2026Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-24068
Last Modified: 20 Feb 2026Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-47969
Last Modified: 20 Feb 2026Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.
CVE-2025-47962
Last Modified: 26 Feb 2026Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.
CVE-2025-33071
Last Modified: 26 Feb 2026Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
CVE-2025-47956
Last Modified: 20 Feb 2026External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
CVE-2025-47955
Last Modified: 20 Feb 2026Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
CVE-2025-47953
Last Modified: 22 May 2026Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47162
Last Modified: 22 May 2026Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47160
Last Modified: 20 Feb 2026Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
CVE-2025-33075
Last Modified: 20 Feb 2026Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2025-33067
Last Modified: 20 Feb 2026Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
CVE-2025-33066
Last Modified: 20 Feb 2026Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
CVE-2025-33065
Last Modified: 20 Feb 2026Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33064
Last Modified: 20 Feb 2026Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
CVE-2025-33063
Last Modified: 20 Feb 2026Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33062
Last Modified: 20 Feb 2026Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33061
Last Modified: 20 Feb 2026Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33060
Last Modified: 20 Feb 2026Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33059
Last Modified: 20 Feb 2026Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-33058
Last Modified: 20 Feb 2026Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
CVE-2025-32724
Last Modified: 20 Feb 2026Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
