446 Total CVEs
240 AI Analyzed
17 CISA KEV
69 Critical
All Vendors
Showing 1-446 of 446 CVEs
CVE-2026-24838
Analyzed
9.1
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, m...

2026-01-28
CVE-2026-24837
Analyzed
7.6
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem

2026-01-28
CVE-2026-24836
Analyzed
7.6
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem

2026-01-28
CVE-2026-24833
Analyzed
7.6
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem

2026-01-28
CVE-2026-24306
Analyzed
9.8
Microsoft Multiple Products

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

2026-01-23
CVE-2026-24305
Analyzed
9.3
Microsoft Multiple Products

Azure Entra ID Elevation of Privilege Vulnerability

2026-01-23
CVE-2026-24304
Analyzed
9.9
Microsoft Multiple Products

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

2026-01-23
CVE-2026-24016
Analyzed
7.8
Microsoft Multiple Products

The installer of ServerView Agents for Windows provided by Fsas Technologies Inc

2026-01-21
CVE-2026-23512
Analyzed
8.6
Microsoft Multiple Products

SumatraPDF is a multi-format reader for Windows

2026-01-15
CVE-2026-22035
Analyzed
7.7
Microsoft Multiple Products

Greenshot is an open source Windows screenshot utility

2026-01-08
CVE-2026-21524
Analyzed
7.4
Microsoft Multiple Products

Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a netwo...

2026-01-24
CVE-2026-21509
KEV Analyzed
7.8
Microsoft Multiple Products

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally

2026-01-27
CVE-2026-21408
Analyzed
7.3
Microsoft Multiple Products

beat-access for Windows version 3

2026-01-27
CVE-2026-21264
Analyzed
9.3
Microsoft Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform s...

2026-01-23
CVE-2026-21227
Analyzed
8.2
Microsoft Multiple Products

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileg...

2026-01-23
CVE-2026-20963
Analyzed
8.8
Microsoft Multiple Products

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2026-01-14
CVE-2026-20960
Analyzed
8
Microsoft Multiple Products

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network

2026-01-17
CVE-2026-20953
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2026-01-14
CVE-2026-20952
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2026-01-14
CVE-2026-20947
Analyzed
8.8
Microsoft Multiple Products

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to e...

2026-01-14
CVE-2026-20944
Analyzed
8.4
Microsoft Multiple Products

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally

2026-01-14
CVE-2026-20931
8
Microsoft Multiple Products

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network

2026-01-14
CVE-2026-20868
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2026-01-14
CVE-2026-20861
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attack...

2026-01-15
CVE-2026-20860
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevat...

2026-01-15
CVE-2026-20859
7.8
Microsoft Multiple Products

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally

2026-01-15
CVE-2026-20858
7.8
Microsoft Multiple Products

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally

2026-01-15
CVE-2026-20857
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally

2026-01-15
CVE-2026-20856
8.1
Microsoft Multiple Products

Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network

2026-01-14
CVE-2026-20843
Analyzed
7.8
Microsoft Multiple Products

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally

2026-01-15
CVE-2026-20840
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally

2026-01-15
CVE-2026-20837
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally

2026-01-15
CVE-2026-20832
Analyzed
7.8
Microsoft Multiple Products

Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability

2026-01-14
CVE-2026-20831
7.8
Microsoft Multiple Products

Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges...

2026-01-14
CVE-2026-20826
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows...

2026-01-14
CVE-2026-20822
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally

2026-01-14
CVE-2026-20820
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally

2026-01-14
CVE-2026-20817
7.8
Microsoft Multiple Products

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally

2026-01-14
CVE-2026-20816
7.8
Microsoft Multiple Products

Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally

2026-01-14
CVE-2026-20811
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally

2026-01-14
CVE-2026-20810
7.8
Microsoft Multiple Products

Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally

2026-01-14
CVE-2026-20809
7.8
Microsoft Multiple Products

Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally

2026-01-14
CVE-2026-20805
KEV
9.5
Microsoft Windows

Microsoft Windows Information Disclosure Vulnerability - Active in CISA KEV catalog.

2026-01-14
CVE-2025-9844
Analyzed
8.8
Microsoft Multiple Products

Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable

2025-09-23
CVE-2025-9491
Analyzed
7
Microsoft Multiple Products

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability

2025-08-26
CVE-2025-9142
Analyzed
7.5
Microsoft Multiple Products

A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory

2026-01-16
CVE-2025-8069
Analyzed
7.8
Microsoft Multiple Products

During the AWS Client VPN client installation on Windows devices, the install process references the C:\usr\local\windows-x86_64-openssl-localbuild\ss...

2025-07-23
CVE-2025-7619
Analyzed
8.8
Microsoft Multiple Products

BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability

2025-07-14
CVE-2025-7472
Analyzed
7.5
Microsoft Multiple Products

A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1

2025-07-17
CVE-2025-7433
Analyzed
8.8
Microsoft Multiple Products

A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025

2025-07-17
CVE-2025-7007
Analyzed
7.5
Microsoft Multiple Products

NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the anti...

2025-12-02
CVE-2025-67781
Analyzed
9.9
Microsoft Multiple Products

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privilege...

2025-12-18
CVE-2025-67506
Analyzed
9.8
Microsoft Multiple Products

PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/r...

2025-12-11
CVE-2025-67460
Analyzed
7.8
Microsoft Multiple Products

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6

2025-12-11
CVE-2025-66495
Analyzed
7.8
Microsoft Multiple Products

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025

2025-12-20
CVE-2025-65041
Analyzed
10
Microsoft Multiple Products

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

2025-12-19
CVE-2025-65037
Analyzed
10
Microsoft Multiple Products

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

2025-12-19
CVE-2025-64740
Analyzed
7.5
Microsoft Multiple Products

Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an authenticated user to conduct...

2025-11-14
CVE-2025-64695
Analyzed
7.8
Microsoft Multiple Products

Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows)

2025-11-22
CVE-2025-64693
Analyzed
9.8
Microsoft Multiple Products

Security Point (Windows) of MaLion and MaLionCloud contains a heap-based buffer overflow vulnerability in processing Content-Length. Receiving a speci...

2025-11-26
CVE-2025-64680
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally

2025-12-11
CVE-2025-64679
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally

2025-12-11
CVE-2025-64678
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-12-10
CVE-2025-64677
Analyzed
8.2
Microsoft Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker t...

2025-12-19
CVE-2025-64675
Analyzed
8.3
Microsoft Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spo...

2025-12-19
CVE-2025-64672
8.8
Microsoft Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to p...

2025-12-10
CVE-2025-64669
Analyzed
7.8
Microsoft Multiple Products

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally

2025-12-12
CVE-2025-64661
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate...

2025-12-10
CVE-2025-64657
Analyzed
9.8
Microsoft Multiple Products

Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.

2025-11-27
CVE-2025-64405
7.5
Microsoft Multiple Products

Apache OpenOffice documents can contain links

2025-11-14
CVE-2025-64404
7.5
Microsoft Multiple Products

Apache OpenOffice documents can contain links to other files

2025-11-14
CVE-2025-64403
Analyzed
8.1
Microsoft Multiple Products

Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources"

2025-11-13
CVE-2025-64401
7.5
Microsoft Multiple Products

Apache OpenOffice documents can contain links

2025-11-14
CVE-2025-64140
Analyzed
8.8
Microsoft Multiple Products

Jenkins Azure CLI Plugin 0

2025-10-29
CVE-2025-64095
Analyzed
10
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor...

2025-10-28
CVE-2025-63680
Analyzed
8.6
Microsoft Multiple Products

Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecuteW fallb...

2025-11-15
CVE-2025-63406
Analyzed
8.8
Microsoft Multiple Products

An issue in Intermesh BV GroupOffice vulnerable before v

2025-11-15
CVE-2025-62931
Analyzed
8.8
Microsoft Multiple Products

Missing Authorization vulnerability in microsoftstart MSN Partner Hub microsoft-start allows Exploiting Incorrectly Configured Access Control Security...

2025-10-28
CVE-2025-62776
Analyzed
7.8
Microsoft Multiple Products

The installer of WTW EAGLE (for Windows) 3

2025-10-29
CVE-2025-62691
Analyzed
9.8
Microsoft Multiple Products

Security Point (Windows) of MaLion and MaLionCloud contains a stack-based buffer overflow vulnerability in processing HTTP headers. Receiving a specia...

2025-11-26
CVE-2025-62571
7.8
Microsoft Multiple Products

Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62564
7.8
Microsoft Multiple Products

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-62563
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-62562
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-62561
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-62560
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-62559
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-62558
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-62557
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-62556
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-62554
8.4
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-62553
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-62552
7.8
Microsoft Multiple Products

Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally

2025-12-10
CVE-2025-62550
8.8
Microsoft Multiple Products

Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network

2025-12-10
CVE-2025-62549
Analyzed
8.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-12-10
CVE-2025-62474
Analyzed
7.8
Microsoft Multiple Products

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62472
Analyzed
7.8
Microsoft Multiple Products

Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62470
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62467
7.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62466
7.8
Microsoft Multiple Products

Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62464
7.8
Microsoft Multiple Products

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62462
7.8
Microsoft Multiple Products

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62461
7.8
Microsoft Multiple Products

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62459
Analyzed
8.3
Microsoft Multiple Products

Microsoft Defender Portal Spoofing Vulnerability

2025-11-20
CVE-2025-62458
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62457
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62456
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network

2025-12-10
CVE-2025-62455
7.8
Microsoft Multiple Products

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62454
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62452
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-11-13
CVE-2025-62221
KEV Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-62220
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network

2025-11-13
CVE-2025-62216
7.8
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2025-11-13
CVE-2025-62215
KEV
9.5
Microsoft Windows

Microsoft Windows Race Condition Vulnerability - Active in CISA KEV catalog.

2025-11-13
CVE-2025-62207
Analyzed
8.6
Microsoft Multiple Products

Azure Monitor Elevation of Privilege Vulnerability

2025-11-20
CVE-2025-62205
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally

2025-11-13
CVE-2025-62204
Analyzed
8
Microsoft Multiple Products

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-11-13
CVE-2025-62203
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-11-13
CVE-2025-62201
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-11-13
CVE-2025-62200
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-11-13
CVE-2025-62199
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2025-11-13
CVE-2025-61973
Analyzed
8.8
Microsoft Multiple Products

A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store

2026-01-16
CVE-2025-61582
Analyzed
7.5
Microsoft Multiple Products

TS3 Manager is modern web interface for maintaining Teamspeak3 servers

2025-10-02
CVE-2025-61303
Analyzed
9.8
Microsoft Multiple Products

Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behavioral ana...

2025-10-21
CVE-2025-60727
7.8
Microsoft Multiple Products

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-11-13
CVE-2025-60721
7.8
Microsoft Multiple Products

Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-60720
7.8
Microsoft Multiple Products

Buffer over-read in Windows TDX

2025-11-13
CVE-2025-60718
7.8
Microsoft Multiple Products

Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-60715
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-11-13
CVE-2025-60714
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally

2025-11-13
CVE-2025-60713
Analyzed
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-60710
7.8
Microsoft Multiple Products

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges l...

2025-11-13
CVE-2025-60709
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-60705
7.8
Microsoft Multiple Products

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-60703
Analyzed
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-59775
7.5
Microsoft Multiple Products

Server-Side Request Forgery (SSRF) vulnerability  in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off  allows to pot...

2025-12-06
CVE-2025-59545
Analyzed
9
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt modu...

2025-09-23
CVE-2025-59517
7.8
Microsoft Multiple Products

Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-59516
7.8
Microsoft Multiple Products

Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-59514
7.8
Microsoft Multiple Products

Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-59511
7.8
Microsoft Multiple Products

External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-59505
7.8
Microsoft Multiple Products

Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally

2025-11-13
CVE-2025-59503
Analyzed
9.9
Microsoft Multiple Products

Server-side request forgery (ssrf) in Azure Compute Gallery allows an authorized attacker to elevate privileges over a network.

2025-10-23
CVE-2025-59500
Analyzed
7.7
Microsoft Multiple Products

Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network

2025-10-23
CVE-2025-59292
8.2
Microsoft Multiple Products

External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-59291
8.2
Microsoft Multiple Products

External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-59287
KEV Analyzed
9.8
Microsoft Multiple Products

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

2025-10-14
CVE-2025-59278
7.8
Microsoft Multiple Products

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally

2025-10-15
CVE-2025-59277
7.8
Microsoft Multiple Products

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-59275
7.8
Microsoft Multiple Products

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-59273
Analyzed
7.3
Microsoft Multiple Products

Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network

2025-10-23
CVE-2025-59255
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-59254
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-59251
Analyzed
7.6
Microsoft Multiple Products

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

2025-09-24
CVE-2025-59249
8.8
Microsoft Multiple Products

Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network

2025-10-14
CVE-2025-59247
Analyzed
8.8
Microsoft Multiple Products

Azure PlayFab Elevation of Privilege Vulnerability

2025-10-09
CVE-2025-59246
Analyzed
9.8
Microsoft Multiple Products

Azure Entra ID Elevation of Privilege Vulnerability

2025-10-09
CVE-2025-59245
Analyzed
9.8
Microsoft Multiple Products

Microsoft SharePoint Online Elevation of Privilege Vulnerability

2025-11-20
CVE-2025-59243
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-10-14
CVE-2025-59242
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-59241
7.8
Microsoft Multiple Products

Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allows an authorized attacker to el...

2025-10-14
CVE-2025-59238
7.8
Microsoft Multiple Products

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally

2025-10-14
CVE-2025-59237
Analyzed
8.8
Microsoft Multiple Products

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-10-14
CVE-2025-59236
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-10-14
CVE-2025-59234
7.8
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2025-10-14
CVE-2025-59233
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-10-14
CVE-2025-59231
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-10-14
CVE-2025-59230
KEV Analyzed
7.8
Microsoft Multiple Products

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-59228
8.8
Microsoft Multiple Products

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-10-14
CVE-2025-59227
7.8
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2025-10-14
CVE-2025-59226
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally

2025-10-14
CVE-2025-59225
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-10-14
CVE-2025-59224
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-10-14
CVE-2025-59223
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-10-14
CVE-2025-59222
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally

2025-10-14
CVE-2025-59220
Analyzed
7
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker...

2025-09-18
CVE-2025-59218
Analyzed
9.6
Microsoft Multiple Products

Azure Entra ID Elevation of Privilege Vulnerability

2025-10-09
CVE-2025-59216
Analyzed
7
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attac...

2025-09-18
CVE-2025-59215
Analyzed
7
Microsoft Multiple Products

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally

2025-09-18
CVE-2025-59213
Analyzed
8.4
Microsoft Multiple Products

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacke...

2025-10-14
CVE-2025-59207
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-59187
7.8
Microsoft Multiple Products

Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-59050
Analyzed
8.4
Microsoft Multiple Products

Greenshot is an open source Windows screenshot utility

2025-09-16
CVE-2025-59033
Analyzed
9.8
Microsoft Multiple Products

The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. On systems that do not have hyperviso...

2025-09-08
CVE-2025-58728
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58724
7.8
Microsoft Multiple Products

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58722
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58720
7.8
Microsoft Multiple Products

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information l...

2025-10-14
CVE-2025-58716
8.8
Microsoft Multiple Products

Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58715
8.8
Microsoft Multiple Products

Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58714
7.8
Microsoft Multiple Products

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-58323
7.7
Microsoft Multiple Products

NAVER MYBOX Explorer for Windows before 3

2025-08-29
CVE-2025-58322
7.8
Microsoft Multiple Products

NAVER MYBOX Explorer for Windows before 3

2025-08-28
CVE-2025-57870
Analyzed
10
Microsoft Multiple Products

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a...

2025-10-22
CVE-2025-57625
Analyzed
8.8
Microsoft Multiple Products

CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability

2025-09-17
CVE-2025-56803
Analyzed
8.4
Microsoft Multiple Products

Figma Desktop for Windows version 125

2025-09-03
CVE-2025-55701
7.8
Microsoft Multiple Products

Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-55697
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-55694
7.8
Microsoft Multiple Products

Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-55692
7.8
Microsoft Multiple Products

Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-55680
7.8
Microsoft Multiple Products

Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locall...

2025-10-14
CVE-2025-55677
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-55339
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-55328
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevat...

2025-10-14
CVE-2025-55321
Analyzed
8.7
Microsoft Multiple Products

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an authorized attacker to perform spoofin...

2025-10-09
CVE-2025-55317
7.8
Microsoft Multiple Products

Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges local...

2025-09-09
CVE-2025-55316
7.8
Microsoft Multiple Products

External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-55312
Analyzed
7.8
Microsoft Multiple Products

An issue was discovered in Foxit PDF and Editor for Windows before 13

2025-12-12
CVE-2025-55244
Analyzed
9
Microsoft Multiple Products

Azure Bot Service Elevation of Privilege Vulnerability

2025-09-05
CVE-2025-55241
Analyzed
9
Microsoft Multiple Products

Azure Entra Elevation of Privilege Vulnerability

2025-09-05
CVE-2025-55233
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally

2025-12-10
CVE-2025-55232
Analyzed
9.8
Microsoft Multiple Products

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network.

2025-09-09
CVE-2025-55231
Analyzed
7.5
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to exec...

2025-08-21
CVE-2025-55230
Analyzed
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally

2025-08-21
CVE-2025-55228
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to...

2025-09-09
CVE-2025-55224
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to...

2025-09-09
CVE-2025-55077
Analyzed
7.4
Microsoft Multiple Products

Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the remo...

2025-08-07
CVE-2025-54918
8.8
Microsoft Multiple Products

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network

2025-09-09
CVE-2025-54916
7.8
Microsoft Multiple Products

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally

2025-09-09
CVE-2025-54914
Analyzed
10
Microsoft Multiple Products

Azure Networking Elevation of Privilege Vulnerability

2025-09-05
CVE-2025-54913
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an autho...

2025-09-09
CVE-2025-54912
7.8
Microsoft Multiple Products

Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54910
Analyzed
8.4
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally

2025-09-09
CVE-2025-54908
7.8
Microsoft Multiple Products

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally

2025-09-09
CVE-2025-54907
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally

2025-09-09
CVE-2025-54906
7.8
Microsoft Multiple Products

Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally

2025-09-09
CVE-2025-54904
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-09-09
CVE-2025-54903
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-09-09
CVE-2025-54902
7.8
Microsoft Multiple Products

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-09-09
CVE-2025-54900
Analyzed
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-09-09
CVE-2025-54899
7.8
Microsoft Multiple Products

Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-09-09
CVE-2025-54898
7.8
Microsoft Multiple Products

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-09-09
CVE-2025-54897
Analyzed
8.8
Microsoft Multiple Products

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-09-09
CVE-2025-54896
Analyzed
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-09-09
CVE-2025-54895
7.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54882
Analyzed
7.1
Microsoft Multiple Products

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune

2025-08-07
CVE-2025-54113
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-09-09
CVE-2025-54111
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54110
8.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54106
Analyzed
8.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-09-09
CVE-2025-54102
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54100
7.8
Microsoft Multiple Products

Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute c...

2025-12-10
CVE-2025-54098
7.8
Microsoft Multiple Products

Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-54092
7.8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevat...

2025-09-09
CVE-2025-54091
7.8
Microsoft Multiple Products

Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-53947
Analyzed
7.7
Microsoft Multiple Products

A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerability to corrupt sensitive data

2025-09-18
CVE-2025-53801
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-53800
7.8
Microsoft Multiple Products

No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-53795
Analyzed
9.1
Microsoft Multiple Products

Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.

2025-08-21
CVE-2025-53792
Analyzed
9.1
Microsoft Multiple Products

Azure Portal Elevation of Privilege Vulnerability

2025-08-07
CVE-2025-53789
7.8
Microsoft Multiple Products

Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally

2025-08-13
CVE-2025-53787
Analyzed
8.2
Microsoft Multiple Products

Microsoft 365 Copilot BizChat Information Disclosure Vulnerability

2025-08-07
CVE-2025-53786
Analyzed
8
Microsoft Multiple Products

On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix

2025-08-07
CVE-2025-53784
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53782
8.4
Microsoft Multiple Products

Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally

2025-10-14
CVE-2025-53778
8.8
Microsoft Multiple Products

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network

2025-08-12
CVE-2025-53770
KEV
9.8
Microsoft SharePoint Server

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft...

2025-07-21
CVE-2025-53767
Analyzed
10
Microsoft Multiple Products

Azure OpenAI Elevation of Privilege Vulnerability

2025-08-07
CVE-2025-53766
Analyzed
9.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

2025-08-12
CVE-2025-53763
Analyzed
9.8
Microsoft Multiple Products

Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

2025-08-21
CVE-2025-53761
7.8
Microsoft Multiple Products

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally

2025-08-13
CVE-2025-53759
7.8
Microsoft Multiple Products

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-08-13
CVE-2025-53741
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-08-13
CVE-2025-53740
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53739
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-08-13
CVE-2025-53738
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally

2025-08-13
CVE-2025-53737
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53735
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53734
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53733
8.4
Microsoft Multiple Products

Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53732
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53731
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53730
7.8
Microsoft Multiple Products

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally

2025-08-12
CVE-2025-53729
7.8
Microsoft Multiple Products

Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-53726
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locall...

2025-08-12
CVE-2025-53725
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locall...

2025-08-12
CVE-2025-53724
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locall...

2025-08-12
CVE-2025-53723
7.8
Microsoft Multiple Products

Numeric truncation error in Windows Hyper-V allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-53720
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-53155
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-53154
7.8
Microsoft Multiple Products

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-53152
7.8
Microsoft Multiple Products

Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally

2025-08-12
CVE-2025-53151
7.8
Microsoft Multiple Products

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-53150
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-53145
8.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-53144
8.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-53143
8.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-53141
7.8
Microsoft Multiple Products

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-53133
7.8
Microsoft Multiple Products

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-53132
8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to...

2025-08-12
CVE-2025-53131
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network

2025-08-12
CVE-2025-52451
Analyzed
8.5
Microsoft Multiple Products

Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allo...

2025-08-23
CVE-2025-51735
Analyzed
7.5
Microsoft Multiple Products

CSV formula injection vulnerability in HCL Technologies Ltd

2025-11-29
CVE-2025-50255
Analyzed
7.8
Microsoft Multiple Products

Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2

2025-09-18
CVE-2025-50177
Analyzed
8.1
Microsoft Multiple Products

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network

2025-08-12
CVE-2025-50175
Analyzed
7.8
Microsoft Multiple Products

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-50173
7.8
Microsoft Multiple Products

Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-50170
7.8
Microsoft Multiple Products

Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privile...

2025-08-12
CVE-2025-50168
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-50165
Analyzed
9.8
Microsoft Multiple Products

Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

2025-08-12
CVE-2025-50164
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-50163
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-08-12
CVE-2025-50162
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-50160
Analyzed
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-50155
7.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locall...

2025-08-12
CVE-2025-50153
7.8
Microsoft Multiple Products

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-50152
7.8
Microsoft Multiple Products

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-10-14
CVE-2025-49761
7.8
Microsoft Multiple Products

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally

2025-08-12
CVE-2025-49757
Analyzed
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-08-12
CVE-2025-49753
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49752
Analyzed
10
Microsoft Multiple Products

Azure Bastion Elevation of Privilege Vulnerability

2025-11-20
CVE-2025-49741
7.4
Microsoft Multiple Products

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network

2025-07-06
CVE-2025-49740
8.8
Microsoft Multiple Products

Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network

2025-07-08
CVE-2025-49735
8.1
Microsoft Multiple Products

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network

2025-07-10
CVE-2025-49729
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49724
8.8
Microsoft Multiple Products

Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49723
8.8
Microsoft Multiple Products

Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally

2025-07-08
CVE-2025-49713
Analyzed
8.8
Microsoft Multiple Products

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over...

2025-07-05
CVE-2025-49712
Analyzed
8.8
Microsoft Multiple Products

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-08-12
CVE-2025-49708
Analyzed
9.9
Microsoft Multiple Products

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.

2025-10-14
CVE-2025-49707
7.9
Microsoft Multiple Products

Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally

2025-08-12
CVE-2025-49704
8.8
Microsoft Multiple Products

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-07-08
CVE-2025-49701
Analyzed
8.8
Microsoft Multiple Products

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network

2025-07-08
CVE-2025-49697
8.4
Microsoft Multiple Products

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally

2025-07-08
CVE-2025-49696
8.4
Microsoft Multiple Products

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally

2025-07-08
CVE-2025-49695
Analyzed
8.4
Microsoft Multiple Products

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally

2025-07-08
CVE-2025-49692
7.8
Microsoft Multiple Products

Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally

2025-09-09
CVE-2025-49691
8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network

2025-07-10
CVE-2025-49688
8.8
Microsoft Multiple Products

Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49687
8.8
Microsoft Multiple Products

Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally

2025-07-08
CVE-2025-49676
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49674
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49673
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49672
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49670
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49669
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49668
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49663
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49657
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-49459
7.8
Microsoft Multiple Products

Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6

2025-09-09
CVE-2025-49457
Analyzed
9.6
Microsoft Multiple Products

Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access

2025-08-12
CVE-2025-48982
Analyzed
7.3
Microsoft Multiple Products

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a ma...

2025-10-31
CVE-2025-48824
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-48822
8.6
Microsoft Multiple Products

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally

2025-07-08
CVE-2025-47998
8.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network

2025-07-08
CVE-2025-47987
7.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47985
7.8
Microsoft Multiple Products

Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47982
7.8
Microsoft Multiple Products

Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47981
Analyzed
9.8
Microsoft Multiple Products

Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.

2025-07-08
CVE-2025-47976
7.8
Microsoft Multiple Products

Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-47972
8
Microsoft Multiple Products

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorize...

2025-07-10
CVE-2025-47761
Analyzed
7.8
Microsoft Multiple Products

An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] in Fortinet FortiClientWindows 7

2025-11-19
CVE-2025-47178
8
Microsoft Multiple Products

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker...

2025-07-10
CVE-2025-47159
7.8
Microsoft Multiple Products

Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally

2025-07-10
CVE-2025-46373
Analyzed
7.8
Microsoft Multiple Products

A Heap-based Buffer Overflow vulnerability [CWE-122] in Fortinet FortiClientWindows 7

2025-11-19
CVE-2025-41246
Analyzed
7.6
Microsoft Multiple Products

VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls

2025-09-29
CVE-2025-40549
Analyzed
9.1
Microsoft Multiple Products

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to...

2025-11-19
CVE-2025-40548
Analyzed
9.1
Microsoft Multiple Products

A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code....

2025-11-19
CVE-2025-40547
Analyzed
9.1
Microsoft Multiple Products

A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute cod...

2025-11-19
CVE-2025-4044
Analyzed
8.2
Microsoft Multiple Products

Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information...

2025-08-19
CVE-2025-37735
Analyzed
7
Microsoft Multiple Products

Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service...

2025-11-06
CVE-2025-36853
Analyzed
7.5
Microsoft Multiple Products

A vulnerability (CVE-2025-21172) exists in msdia140

2025-09-08
CVE-2025-36640
Analyzed
8.8
Microsoft Multiple Products

A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation of...

2026-01-14
CVE-2025-36384
Analyzed
8.4
Microsoft Multiple Products

IBM Db2 for Windows 12

2026-01-31
CVE-2025-36184
Analyzed
7.2
Microsoft Multiple Products

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11

2026-01-31
CVE-2025-35971
8.2
Microsoft Multiple Products

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23

2025-11-13
CVE-2025-35055
Analyzed
8.8
Microsoft Multiple Products

Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp

2025-10-09
CVE-2025-35050
Analyzed
9.8
Microsoft Multiple Products

Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to exe...

2025-10-09
CVE-2025-3500
Analyzed
9
Microsoft Multiple Products

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from...

2025-12-02
CVE-2025-33229
7.3
Microsoft Multiple Products

NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitrary code with the same privileg...

2026-01-21
CVE-2025-33218
Analyzed
7.8
Microsoft Multiple Products

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm

2026-01-29
CVE-2025-33217
Analyzed
7.8
Microsoft Multiple Products

NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free

2026-01-29
CVE-2025-33073
KEV
9.5
Microsoft Windows

Microsoft Windows SMB Client Improper Access Control Vulnerability - Active in CISA KEV catalog.

2025-10-20
CVE-2025-30255
8.2
Microsoft Multiple Products

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23

2025-11-13
CVE-2025-27713
7.8
Microsoft Multiple Products

Out-of-bounds write for some Intel(R) QAT Windows software before version 2

2025-11-13
CVE-2025-27461
7.6
Microsoft Multiple Products

During startup, the device automatically logs in the EPC2 Windows user without requesting a password

2025-07-06
CVE-2025-26513
Analyzed
7
Microsoft Multiple Products

The installer for SAN Host Utilities for Windows versions prior to 8

2025-08-07
CVE-2025-26496
Analyzed
9.6
Microsoft Multiple Products

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Uplo...

2025-08-23
CVE-2025-24990
KEV Analyzed
7.8
Microsoft Multiple Products

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems

2025-10-14
CVE-2025-24052
7.8
Microsoft Multiple Products

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems

2025-10-14
CVE-2025-23358
Analyzed
8.2
Microsoft Multiple Products

NVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path element issue

2025-11-04
CVE-2025-23331
7.5
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocation with excessive size value,...

2025-08-07
CVE-2025-23329
Analyzed
7.5
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause memory corruption by identifying and acces...

2025-09-17
CVE-2025-23328
Analyzed
7.5
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write through a specially...

2025-09-17
CVE-2025-23327
7.5
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through specially craf...

2025-08-07
CVE-2025-23326
7.5
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through a specially cr...

2025-08-07
CVE-2025-23325
Analyzed
7.5
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause uncontrolled recursion through a specially...

2025-08-07
CVE-2025-23324
Analyzed
7.5
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overflow or wraparound, leading to a...

2025-08-07
CVE-2025-23323
Analyzed
7.5
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overflow or wraparound, leading to a...

2025-08-07
CVE-2025-23322
Analyzed
7.5
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple requests could cause a double free when a stream is cance...

2025-08-07
CVE-2025-23321
Analyzed
7.5
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a divide by zero issue by issuing an invalid re...

2025-08-07
CVE-2025-23320
Analyzed
7.5
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause the shared memory l...

2025-08-07
CVE-2025-23319
Analyzed
8.1
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds wr...

2025-08-07
CVE-2025-23318
Analyzed
8.1
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds wr...

2025-08-07
CVE-2025-23316
Analyzed
9.8
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote code execu...

2025-09-17
CVE-2025-23310
Analyzed
9.8
Microsoft Multiple Products

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer overflow by specially crafted...

2025-08-07
CVE-2025-23297
Analyzed
7.8
Microsoft Multiple Products

NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unprivileged ac...

2025-10-01
CVE-2025-23281
Analyzed
7
Microsoft Multiple Products

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can win a race condition might be...

2025-08-04
CVE-2025-23278
Analyzed
7.1
Microsoft Multiple Products

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index validation by issuing a call with...

2025-08-04
CVE-2025-23277
Analyzed
7.3
Microsoft Multiple Products

NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bounds p...

2025-08-04
CVE-2025-23276
Analyzed
7.8
Microsoft Multiple Products

NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges

2025-08-04
CVE-2025-20387
Analyzed
8
Microsoft Multiple Products

In Splunk Universal Forwarder for Windows versions below 10

2025-12-03
CVE-2025-20386
Analyzed
8
Microsoft Multiple Products

In Splunk Enterprise for Windows versions below 10

2025-12-03
CVE-2025-20239
Analyzed
8.6
Microsoft Multiple Products

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appli...

2025-08-14
CVE-2025-14733
KEV
9.8
Microsoft Multiple Products

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerabili...

2025-12-20
CVE-2025-14237
Analyzed
9.8
Microsoft Multiple Products

Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network s...

2026-01-16
CVE-2025-14236
Analyzed
9.8
Microsoft Multiple Products

Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment...

2026-01-16
CVE-2025-14235
Analyzed
9.8
Microsoft Multiple Products

Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the netwo...

2026-01-16
CVE-2025-14234
Analyzed
9.8
Microsoft Multiple Products

Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segmen...

2026-01-16
CVE-2025-14233
Analyzed
9.8
Microsoft Multiple Products

Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network...

2026-01-16
CVE-2025-14232
Analyzed
9.8
Microsoft Multiple Products

Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network...

2026-01-16
CVE-2025-14231
Analyzed
9.8
Microsoft Multiple Products

Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network...

2026-01-16
CVE-2025-14218
Analyzed
7.3
Microsoft Multiple Products

A security flaw has been discovered in code-projects Currency Exchange System 1

2025-12-09
CVE-2025-14217
Analyzed
7.3
Microsoft Multiple Products

A vulnerability was identified in code-projects Currency Exchange System 1

2025-12-09
CVE-2025-14216
Analyzed
7.3
Microsoft Multiple Products

A vulnerability was determined in code-projects Currency Exchange System 1

2025-12-09
CVE-2025-14215
Analyzed
7.3
Microsoft Multiple Products

A vulnerability was found in code-projects Currency Exchange System 1

2025-12-09
CVE-2025-12865
Analyzed
8.8
Microsoft Multiple Products

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to...

2025-11-11
CVE-2025-12864
Analyzed
8.8
Microsoft Multiple Products

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to...

2025-11-11
CVE-2025-12726
Analyzed
7.5
Microsoft Multiple Products

Inappropriate implementation in Views in Google Chrome on Windows prior to 142

2025-11-11
CVE-2025-12055
Analyzed
7.5
Microsoft Multiple Products

HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance...

2025-10-27
CVE-2025-11719
Analyzed
9.8
Microsoft Multiple Products

Starting in Firefox 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corrup...

2025-10-15
CVE-2025-11713
Analyzed
8.1
Microsoft Multiple Products

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows

2025-10-15
CVE-2025-11575
Analyzed
7.8
Microsoft Multiple Products

Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation

2025-10-23
CVE-2025-11020
Analyzed
8.8
Microsoft Multiple Products

An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly exploits Unrestricted Upload of...

2025-10-02
CVE-2025-11001
Analyzed
7
Microsoft Multiple Products

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability

2025-11-20
CVE-2025-10714
Analyzed
8.4
Microsoft Multiple Products

AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows...

2025-11-13
CVE-2025-10491
Analyzed
7.8
Microsoft Multiple Products

The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to...

2025-09-15
CVE-2025-10226
Analyzed
9.8
Microsoft Multiple Products

Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One 2.0.8 and earlier on Windows and Linux allo...

2025-09-10
CVE-2025-10220
Analyzed
9.8
Microsoft Multiple Products

Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows all...

2025-09-10
CVE-2025-10199
7.8
Microsoft Multiple Products

A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025

2025-09-10
CVE-2025-10198
7.8
Microsoft Multiple Products

Sunshine for Windows, version v2025

2025-09-10
CVE-2024-56179
Analyzed
7.8
Microsoft Multiple Products

In MindManager Windows versions prior to 24

2025-08-23
CVE-2024-13972
Analyzed
8.8
Microsoft Multiple Products

A vulnerability related to registry permissions in the Intercept X for Windows updater prior to version 2024

2025-07-17
CVE-2023-54330
Analyzed
9.8
Microsoft Multiple Products

Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute ar...

2026-01-14
CVE-2022-50935
9.8
Microsoft Multiple Products

Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path...

2026-01-14
CVE-2021-43226
KEV
9.5
Microsoft Windows

Microsoft Windows Privilege Escalation Vulnerability - Active in CISA KEV catalog.

2025-10-06
CVE-2020-37047
Analyzed
7.8
Microsoft Multiple Products

Deep Instinct Windows Agent 1

2026-02-02
CVE-2020-37000
Analyzed
9.8
Microsoft Multiple Products

Free MP3 CD Ripper 2.8 contains a stack buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting a malicious W...

2026-01-30
CVE-2020-36934
Analyzed
7.8
Microsoft Multiple Products

Deep Instinct Windows Agent 1

2026-01-26
CVE-2019-25261
7.8
Microsoft Multiple Products

AnyDesk 5

2026-02-04
CVE-2013-3918
KEV
9.5
Microsoft Windows

Microsoft Windows Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.

2025-10-06
CVE-2013-3893
KEV
9.5
Microsoft Internet Explorer

Microsoft Internet Explorer Resource Management Errors Vulnerability - Active in CISA KEV catalog.

2025-08-12
CVE-2011-3402
KEV
9.5
Microsoft Windows

Microsoft Windows Remote Code Execution Vulnerability - Active in CISA KEV catalog.

2025-10-06
CVE-2010-3962
KEV
9.5
Microsoft Internet Explorer

Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability - Active in CISA KEV catalog.

2025-10-06
CVE-2009-0556
KEV
9.5
Microsoft Office

Microsoft Office PowerPoint Code Injection Vulnerability - Active in CISA KEV catalog.

2026-01-08
CVE-2007-0671
KEV
9.5
Microsoft Office

Microsoft Office Excel Remote Code Execution Vulnerability - Active in CISA KEV catalog.

2025-08-12