CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-26642

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    6.8
    Medium

    CVE-2025-26637

    Last Modified: 16 Feb 2026

    Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

    Published: 8 Apr 2025
    6.5
    Medium

    CVE-2025-26635

    Last Modified: 13 Feb 2026

    Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-26639

    Last Modified: 13 Feb 2026

    Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.3
    High

    CVE-2025-26628

    Last Modified: 13 Feb 2026

    Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.

    Published: 8 Apr 2025
    6.8
    Medium

    CVE-2025-25002

    Last Modified: 13 Feb 2026

    Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-24058

    Last Modified: 13 Feb 2026

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    8.8
    High

    CVE-2025-21222

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

    Published: 8 Apr 2025
    8.8
    High

    CVE-2025-21221

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-21204

    Last Modified: 13 Feb 2026

    Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    6.5
    Medium

    CVE-2025-21203

    Last Modified: 13 Feb 2026

    Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 8 Apr 2025
    8.8
    High

    CVE-2025-21205

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

    Published: 8 Apr 2025
    7
    High

    CVE-2025-21191

    Last Modified: 13 Feb 2026

    Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    6.5
    Medium

    CVE-2025-21197

    Last Modified: 13 Feb 2026

    Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-21174

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-24073

    Last Modified: 13 Feb 2026

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-24074

    Last Modified: 13 Feb 2026

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-29824

    Last Modified: 13 Feb 2026

    Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-29823

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-29822

    Last Modified: 13 Feb 2026

    Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-29820

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-29821

    Last Modified: 13 Feb 2026

    Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.

    Published: 8 Apr 2025
    8.8
    High

    CVE-2025-29794

    Last Modified: 13 Feb 2026

    Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 8 Apr 2025
    7.3
    High

    CVE-2025-29792

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.2
    High

    CVE-2025-29793

    Last Modified: 13 Feb 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-29791

    Last Modified: 13 Feb 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27750

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27752

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27751

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27743

    Last Modified: 13 Feb 2026

    Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27749

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27747

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27748

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27746

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27745

    Last Modified: 13 Feb 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 8 Apr 2025
    5.5
    Medium

    CVE-2025-27742

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27744

    Last Modified: 13 Feb 2026

    Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27741

    Last Modified: 13 Feb 2026

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    8.8
    High

    CVE-2025-27740

    Last Modified: 13 Feb 2026

    Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-27479

    Last Modified: 13 Feb 2026

    Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.

    Published: 8 Apr 2025
    7
    High

    CVE-2025-27478

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    8.8
    High

    CVE-2025-27477

    Last Modified: 13 Feb 2026

    Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

    Published: 8 Apr 2025
    7
    High

    CVE-2025-27475

    Last Modified: 13 Feb 2026

    Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-27476

    Last Modified: 13 Feb 2026

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025
    6.5
    Medium

    CVE-2025-27474

    Last Modified: 13 Feb 2026

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

    Published: 8 Apr 2025
    5.4
    Medium

    CVE-2025-27472

    Last Modified: 13 Feb 2026

    Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-27473

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

    Published: 8 Apr 2025
    7.5
    High

    CVE-2025-27470

    Last Modified: 13 Feb 2026

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

    Published: 8 Apr 2025
    5.9
    Medium

    CVE-2025-27471

    Last Modified: 13 Feb 2026

    Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.

    Published: 8 Apr 2025
    7.8
    High

    CVE-2025-26688

    Last Modified: 13 Feb 2026

    Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

    Published: 8 Apr 2025