CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2025-29805

    Last Modified: 13 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-29808

    Last Modified: 13 Feb 2026

    Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.

    Published: 8 Apr 2025
    7.1
    High

    CVE-2025-29809

    Last Modified: 13 Feb 2026

    Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.

    Published: 8 Apr 2025
    7.3
    High

    CVE-2025-29804

    Last Modified: 13 Feb 2026

    Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-29801

    Last Modified: 13 Feb 2026

    Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.3
    High

    CVE-2025-29802

    Last Modified: 13 Feb 2026

    Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-29800

    Last Modified: 13 Feb 2026

    Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27739

    Last Modified: 13 Feb 2026

    Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    6.5
    Medium

    CVE-2025-27738

    Last Modified: 13 Feb 2026

    Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.

    Published: 8 Apr 2025
    8.6
    High

    CVE-2025-27737

    Last Modified: 13 Feb 2026

    Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-27736

    Last Modified: 13 Feb 2026

    Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.

    Published: 8 Apr 2025
    6
    Medium

    CVE-2025-27735

    Last Modified: 13 Feb 2026

    Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27733

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7
    High

    CVE-2025-27732

    Last Modified: 13 Feb 2026

    Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27730

    Last Modified: 13 Feb 2026

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27731

    Last Modified: 13 Feb 2026

    Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27728

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27729

    Last Modified: 13 Feb 2026

    Use after free in Windows Shell allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27727

    Last Modified: 13 Feb 2026

    Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27490

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.1
    High

    CVE-2025-27491

    Last Modified: 13 Feb 2026

    Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.

    Published: 8 Apr 2025
    7
    High

    CVE-2025-27492

    Last Modified: 13 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-27486

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27489

    Last Modified: 13 Feb 2026

    Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    8
    High

    CVE-2025-27487

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27483

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    8.1
    High

    CVE-2025-27482

    Last Modified: 13 Feb 2026

    Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

    Published: 8 Apr 2025
    8.8
    High

    CVE-2025-27481

    Last Modified: 13 Feb 2026

    Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

    Published: 8 Apr 2025
    8.1
    High

    CVE-2025-27480

    Last Modified: 13 Feb 2026

    Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-27484

    Last Modified: 13 Feb 2026

    Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-27485

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-27469

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27467

    Last Modified: 8 Jul 2025

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-26679

    Last Modified: 13 Feb 2026

    Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    8.4
    High

    CVE-2025-26678

    Last Modified: 13 Feb 2026

    Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.

    Published: 8 Apr 2025
    6.5
    Medium

    CVE-2025-26676

    Last Modified: 13 Feb 2026

    Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-26675

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-26673

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

    Published: 8 Apr 2025
    6.5
    Medium

    CVE-2025-26672

    Last Modified: 13 Feb 2026

    Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-26674

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

    Published: 8 Apr 2025
    8.1
    High

    CVE-2025-26671

    Last Modified: 13 Feb 2026

    Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

    Published: 8 Apr 2025
    8.1
    High

    CVE-2025-26670

    Last Modified: 13 Feb 2026

    Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-26652

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

    Published: 8 Apr 2025
    6.5
    Medium

    CVE-2025-26651

    Last Modified: 13 Feb 2026

    Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

    Published: 8 Apr 2025
    8.8
    High

    CVE-2025-26647

    Last Modified: 13 Feb 2026

    Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

    Published: 8 Apr 2025
    7
    High

    CVE-2025-26649

    Last Modified: 13 Feb 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-26648

    Last Modified: 13 Feb 2026

    Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    5.1
    Medium

    CVE-2025-26644

    Last Modified: 13 Feb 2026

    Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-26641

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

    Published: 8 Apr 2025
    7
    High

    CVE-2025-26640

    Last Modified: 13 Feb 2026

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025