CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2025-21392

    Last Modified: 26 Feb 2026

    Microsoft Office Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21390

    Last Modified: 26 Feb 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21387

    Last Modified: 26 Feb 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21386

    Last Modified: 26 Feb 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21381

    Last Modified: 13 Feb 2026

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    6.5
    Medium

    CVE-2025-21377

    Last Modified: 13 Feb 2026

    NTLM Hash Disclosure Spoofing Vulnerability

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-21371

    Last Modified: 26 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21367

    Last Modified: 26 Feb 2026

    Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21359

    Last Modified: 26 Feb 2026

    Windows Kernel Security Feature Bypass Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21358

    Last Modified: 13 Feb 2026

    Windows Core Messaging Elevation of Privileges Vulnerability

    Published: 11 Feb 2025
    5.9
    Medium

    CVE-2025-21350

    Last Modified: 13 Feb 2026

    Windows Kerberos Denial of Service Vulnerability

    Published: 11 Feb 2025
    6.8
    Medium

    CVE-2025-21349

    Last Modified: 26 Feb 2026

    Windows Remote Desktop Configuration Service Tampering Vulnerability

    Published: 11 Feb 2025
    6
    Medium

    CVE-2025-21347

    Last Modified: 13 Feb 2026

    Windows Deployment Services Denial of Service Vulnerability

    Published: 11 Feb 2025
    3.3
    Low

    CVE-2025-21337

    Last Modified: 13 Feb 2026

    Windows NTFS Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    9
    Critical

    CVE-2025-21198

    Last Modified: 26 Feb 2026

    Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-21201

    Last Modified: 26 Feb 2026

    Windows Telephony Server Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-21200

    Last Modified: 26 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-21190

    Last Modified: 26 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-21410

    Last Modified: 26 Feb 2026

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-21407

    Last Modified: 26 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-21406

    Last Modified: 26 Feb 2026

    Windows Telephony Service Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-21208

    Last Modified: 26 Feb 2026

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    7.1
    High

    CVE-2025-21194

    Last Modified: 13 Feb 2026

    Microsoft Surface Security Feature Bypass Vulnerability

    Published: 11 Feb 2025
    5.3
    Medium

    CVE-2025-21259

    Last Modified: 13 Feb 2026

    Microsoft Outlook Spoofing Vulnerability

    Published: 11 Feb 2025
    7.3
    High

    CVE-2025-24039

    Last Modified: 13 Feb 2026

    Visual Studio Code Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    7
    High

    CVE-2025-24036

    Last Modified: 26 Feb 2026

    Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21420

    Last Modified: 13 Feb 2026

    Windows Disk Cleanup Tool Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    7.1
    High

    CVE-2025-21419

    Last Modified: 26 Feb 2026

    Windows Setup Files Cleanup Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21418

    Last Modified: 26 Feb 2026

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    7.1
    High

    CVE-2025-21391

    Last Modified: 26 Feb 2026

    Windows Storage Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    7.4
    High

    CVE-2025-21183

    Last Modified: 26 Feb 2026

    Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    7.4
    High

    CVE-2025-21182

    Last Modified: 26 Feb 2026

    Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21383

    Last Modified: 13 Feb 2026

    Microsoft Excel Information Disclosure Vulnerability

    Published: 11 Feb 2025
    7.1
    High

    CVE-2025-21379

    Last Modified: 13 Feb 2026

    DHCP Client Service Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    8.1
    High

    CVE-2025-21376

    Last Modified: 26 Feb 2026

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    7.8
    High

    CVE-2025-21375

    Last Modified: 13 Feb 2026

    Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-21369

    Last Modified: 13 Feb 2026

    Microsoft Digest Authentication Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    8.8
    High

    CVE-2025-21368

    Last Modified: 13 Feb 2026

    Microsoft Digest Authentication Remote Code Execution Vulnerability

    Published: 11 Feb 2025
    6.5
    Medium

    CVE-2025-21352

    Last Modified: 13 Feb 2026

    Internet Connection Sharing (ICS) Denial of Service Vulnerability

    Published: 11 Feb 2025
    7.5
    High

    CVE-2025-21351

    Last Modified: 13 Feb 2026

    Windows Active Directory Domain Services API Denial of Service Vulnerability

    Published: 11 Feb 2025
    7.3
    High

    CVE-2025-21206

    Last Modified: 13 Feb 2026

    Visual Studio Installer Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    6
    Medium

    CVE-2025-21188

    Last Modified: 26 Feb 2026

    Azure Network Watcher VM Extension Elevation of Privilege Vulnerability

    Published: 11 Feb 2025
    7.5
    High

    CVE-2025-26495

    Last Modified: 29 Oct 2025

    Cleartext Storage of Sensitive Information vulnerability in Salesforce Tableau Server can record the Personal Access Token (PAT) into logging repositories.This issue affects Tableau Server: before 2022.1.3, before 2021.4.8, before 2021.3.13, before 2021.2.14, before 2021.1.16, before 2020.4.19.

    Published: 11 Feb 2025
    6.5
    Medium

    CVE-2025-24422

    Last Modified: 16 Apr 2025

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.

    Published: 11 Feb 2025
    8.7
    High

    CVE-2025-24414

    Last Modified: 26 Feb 2026

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.

    Published: 11 Feb 2025
    5.4
    Medium

    CVE-2025-24437

    Last Modified: 16 Apr 2025

    Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to view or modify select information. Exploitation of this issue does not require user interaction.

    Published: 11 Feb 2025
    9.1
    Critical

    CVE-2025-24434

    Last Modified: 26 Feb 2026

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.

    Published: 11 Feb 2025
    8.7
    High

    CVE-2025-24415

    Last Modified: 26 Feb 2026

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.

    Published: 11 Feb 2025
    8.1
    High

    CVE-2025-24411

    Last Modified: 26 Feb 2026

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access affecting Confidentiality and Integrity. Exploitation of this issue does not require user interaction.

    Published: 11 Feb 2025
    8.7
    High

    CVE-2025-24416

    Last Modified: 26 Feb 2026

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.

    Published: 11 Feb 2025