CVE-2025-29833
Last Modified: 26 Feb 2026Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.
CVE-2025-29832
Last Modified: 13 Feb 2026Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-29831
Last Modified: 26 Feb 2026Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
CVE-2025-29830
Last Modified: 13 Feb 2026Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-29829
Last Modified: 13 Feb 2026Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
CVE-2025-26685
Last Modified: 13 Feb 2026Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2025-27488
Last Modified: 13 Feb 2026Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.
CVE-2025-26677
Last Modified: 13 Feb 2026Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.
CVE-2025-32709
Last Modified: 26 Feb 2026Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2025-21264
Last Modified: 13 Feb 2026Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2025-32706
Last Modified: 26 Feb 2026Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-32703
Last Modified: 13 Feb 2026Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
CVE-2025-32701
Last Modified: 26 Feb 2026Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-30400
Last Modified: 26 Feb 2026Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
CVE-2025-30394
Last Modified: 13 Feb 2026Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.
CVE-2025-29826
Last Modified: 26 Feb 2026Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
CVE-2025-30393
Last Modified: 26 Feb 2026Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-27468
Last Modified: 26 Feb 2026Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2025-30387
Last Modified: 13 Feb 2026Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-30386
Last Modified: 22 May 2026Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-30384
Last Modified: 26 Feb 2026Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
CVE-2025-30383
Last Modified: 26 Feb 2026Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-30382
Last Modified: 13 Feb 2026Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
CVE-2025-30381
Last Modified: 13 Feb 2026Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-30379
Last Modified: 13 Feb 2026Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-30378
Last Modified: 13 Feb 2026Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
CVE-2025-30377
Last Modified: 13 Feb 2026Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-30376
Last Modified: 13 Feb 2026Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-30375
Last Modified: 26 Feb 2026Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-29979
Last Modified: 13 Feb 2026Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-29978
Last Modified: 13 Feb 2026Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-29977
Last Modified: 13 Feb 2026Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-29976
Last Modified: 13 Feb 2026Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.
CVE-2025-29975
Last Modified: 13 Feb 2026Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
CVE-2025-29973
Last Modified: 26 Feb 2026Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
CVE-2025-29971
Last Modified: 13 Feb 2026Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network.
CVE-2025-29970
Last Modified: 13 Feb 2026Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2025-29969
Last Modified: 26 Feb 2026Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.
CVE-2025-29968
Last Modified: 13 Feb 2026Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.
CVE-2025-29967
Last Modified: 13 Feb 2026Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
CVE-2025-29966
Last Modified: 13 Feb 2026Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
CVE-2025-29964
Last Modified: 26 Feb 2026Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
CVE-2025-29960
Last Modified: 13 Feb 2026Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-29959
Last Modified: 13 Feb 2026Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-26684
Last Modified: 13 Feb 2026External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
CVE-2024-36339
Last Modified: 15 Apr 2026A DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
CVE-2024-21960
Last Modified: 15 Apr 2026Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVE-2025-30310
Last Modified: 14 May 2025Dreamweaver Desktop versions 21.4 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2025-23395
Last Modified: 15 Apr 2026Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary locations with `root` ownership, the invoking user's (real) group ownership and file mode 0644. All data written to the Screen PTY will be logged into this file, allowing to escalate to root privileges
CVE-2025-46802
Last Modified: 15 Apr 2026For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.
