CVE Feed

    Dashboard / CVE

    8.2
    High

    CVE-2025-47977

    Last Modified: 20 Feb 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-47968

    Last Modified: 26 Feb 2026

    Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-47176

    Last Modified: 26 Feb 2026

    '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-47175

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-47174

    Last Modified: 20 Feb 2026

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-47173

    Last Modified: 26 Feb 2026

    Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 10 Jun 2025
    8.8
    High

    CVE-2025-47172

    Last Modified: 26 Feb 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 10 Jun 2025
    6.7
    Medium

    CVE-2025-47171

    Last Modified: 26 Feb 2026

    Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-47170

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-47169

    Last Modified: 26 Feb 2026

    Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-47168

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 10 Jun 2025
    8.4
    High

    CVE-2025-47167

    Last Modified: 22 May 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 10 Jun 2025
    8.8
    High

    CVE-2025-47166

    Last Modified: 26 Feb 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-47165

    Last Modified: 26 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 10 Jun 2025
    8.4
    High

    CVE-2025-47164

    Last Modified: 22 May 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 10 Jun 2025
    8.8
    High

    CVE-2025-47163

    Last Modified: 26 Feb 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 10 Jun 2025
    8.8
    High

    CVE-2025-33073

    Last Modified: 26 Feb 2026

    Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

    Published: 10 Jun 2025
    8.1
    High

    CVE-2025-33070

    Last Modified: 26 Feb 2026

    Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.

    Published: 10 Jun 2025
    5.1
    Medium

    CVE-2025-33069

    Last Modified: 20 Feb 2026

    Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.

    Published: 10 Jun 2025
    7.5
    High

    CVE-2025-33068

    Last Modified: 20 Feb 2026

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

    Published: 10 Jun 2025
    6.5
    Medium

    CVE-2025-33057

    Last Modified: 20 Feb 2026

    Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.

    Published: 10 Jun 2025
    7.5
    High

    CVE-2025-33056

    Last Modified: 20 Feb 2026

    Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-33055

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    8.8
    High

    CVE-2025-33053

    Last Modified: 26 Feb 2026

    External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-33052

    Last Modified: 20 Feb 2026

    Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    7.5
    High

    CVE-2025-33050

    Last Modified: 20 Feb 2026

    Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

    Published: 10 Jun 2025
    7.5
    High

    CVE-2025-32725

    Last Modified: 20 Feb 2026

    Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-24065

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-24069

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-24068

    Last Modified: 20 Feb 2026

    Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    4.4
    Medium

    CVE-2025-47969

    Last Modified: 20 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-47962

    Last Modified: 26 Feb 2026

    Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.

    Published: 10 Jun 2025
    8.1
    High

    CVE-2025-33071

    Last Modified: 26 Feb 2026

    Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-47956

    Last Modified: 20 Feb 2026

    External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-47955

    Last Modified: 20 Feb 2026

    Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

    Published: 10 Jun 2025
    8.4
    High

    CVE-2025-47953

    Last Modified: 22 May 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 10 Jun 2025
    8.4
    High

    CVE-2025-47162

    Last Modified: 22 May 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 10 Jun 2025
    5.4
    Medium

    CVE-2025-47160

    Last Modified: 20 Feb 2026

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

    Published: 10 Jun 2025
    7.8
    High

    CVE-2025-33075

    Last Modified: 20 Feb 2026

    Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 10 Jun 2025
    8.4
    High

    CVE-2025-33067

    Last Modified: 20 Feb 2026

    Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

    Published: 10 Jun 2025
    8.8
    High

    CVE-2025-33066

    Last Modified: 20 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-33065

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    8.8
    High

    CVE-2025-33064

    Last Modified: 20 Feb 2026

    Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-33063

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-33062

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-33061

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-33060

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-33059

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    5.5
    Medium

    CVE-2025-33058

    Last Modified: 20 Feb 2026

    Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

    Published: 10 Jun 2025
    7.5
    High

    CVE-2025-32724

    Last Modified: 20 Feb 2026

    Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

    Published: 10 Jun 2025