CVE-2025-26679 | Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-26678 | Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally. | high |
CVE-2025-26676 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | medium |
CVE-2025-26675 | Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-26674 | Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | high |
CVE-2025-26673 | Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | high |
CVE-2025-26672 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | medium |
CVE-2025-26671 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | high |
CVE-2025-26670 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | high |
CVE-2025-26669 | Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | high |
CVE-2025-26668 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | high |
CVE-2025-26667 | Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | medium |
CVE-2025-26666 | Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | high |
CVE-2025-26665 | Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-26664 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | medium |
CVE-2025-26663 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | high |
CVE-2025-26652 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | high |
CVE-2025-26651 | Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. | medium |
CVE-2025-26649 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-26648 | Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-26647 | Improper input validation in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network. | high |
CVE-2025-26644 | Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally. | medium |
CVE-2025-26642 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | high |
CVE-2025-26641 | Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. | high |
CVE-2025-26640 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-26639 | Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-26637 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | medium |
CVE-2025-26635 | Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network. | medium |
CVE-2025-26628 | Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. | high |
CVE-2025-25002 | Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. | medium |
CVE-2025-24074 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-24073 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-24062 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-24060 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-24058 | Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-21222 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | high |
CVE-2025-21221 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | high |
CVE-2025-21205 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | high |
CVE-2025-21204 | Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-21203 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | medium |
CVE-2025-21197 | Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content. | medium |
CVE-2025-21191 | Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. | high |
CVE-2025-21174 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | high |
CVE-2025-32279 | Missing Authorization vulnerability in Shahjada Live Forms. This issue affects Live Forms: from n/a through 4.8.5. | medium |
CVE-2025-32211 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet Broadstreet allows Stored XSS. This issue affects Broadstreet: from n/a through 1.51.2. | medium |
CVE-2025-32164 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in maennchen1.de m1.DownloadList. This issue affects m1.DownloadList: from n/a through 0.21. | medium |
CVE-2025-32117 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetize Pages Light allows Reflected XSS. This issue affects Widgetize Pages Light: from n/a through 3.0. | high |
CVE-2025-30671 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | medium |
CVE-2025-30670 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | medium |
CVE-2025-27443 | Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access. | low |