Searching...
Please wait while we search the database
| CVE ID | Severity | Description | Published | Actions |
|---|---|---|---|---|
|
CVE-2025-55330
|
MEDIUM |
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
|
14 Oct 2025
|
|
|
CVE-2025-55328
|
HIGH |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-55326
|
HIGH |
Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.
|
14 Oct 2025
|
|
|
CVE-2025-55248
|
MEDIUM |
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
|
14 Oct 2025
|
|
|
CVE-2025-55240
|
HIGH |
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-53768
|
HIGH |
Use after free in Xbox allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-53139
|
HIGH |
Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.
|
14 Oct 2025
|
|
|
CVE-2025-50175
|
HIGH |
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-53150
|
HIGH |
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-50152
|
HIGH |
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-53717
|
HIGH |
Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-25004
|
HIGH |
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-48813
|
MEDIUM |
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
|
14 Oct 2025
|
|
|
CVE-2025-59502
|
HIGH |
Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.
|
14 Oct 2025
|
|
|
CVE-2025-59494
|
HIGH |
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-59295
|
HIGH |
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
|
14 Oct 2025
|
|
|
CVE-2025-59294
|
LOW |
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.
|
14 Oct 2025
|
|
|
CVE-2025-59292
|
HIGH |
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-59291
|
HIGH |
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-59290
|
HIGH |
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-59288
|
MEDIUM |
Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.
|
14 Oct 2025
|
|
|
CVE-2025-59284
|
LOW |
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
|
14 Oct 2025
|
|
|
CVE-2025-59282
|
HIGH |
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
|
14 Oct 2025
|
|
|
CVE-2025-59281
|
HIGH |
Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
|
14 Oct 2025
|
|
|
CVE-2025-47979
|
MEDIUM |
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
|
14 Oct 2025
|
CVE-2025-55330
MEDIUM
14 Oct 2025
Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2025-55328
HIGH
14 Oct 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
CVE-2025-55326
HIGH
14 Oct 2025
Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.
CVE-2025-55248
MEDIUM
14 Oct 2025
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
CVE-2025-55240
HIGH
14 Oct 2025
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-53768
HIGH
14 Oct 2025
Use after free in Xbox allows an authorized attacker to elevate privileges locally.
CVE-2025-53139
HIGH
14 Oct 2025
Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.
CVE-2025-50175
HIGH
14 Oct 2025
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-53150
HIGH
14 Oct 2025
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
CVE-2025-50152
HIGH
14 Oct 2025
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2025-53717
HIGH
14 Oct 2025
Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
CVE-2025-25004
HIGH
14 Oct 2025
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2025-48813
MEDIUM
14 Oct 2025
Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.
CVE-2025-59502
HIGH
14 Oct 2025
Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.
CVE-2025-59494
HIGH
14 Oct 2025
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-59295
HIGH
14 Oct 2025
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
CVE-2025-59294
LOW
14 Oct 2025
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.
CVE-2025-59292
HIGH
14 Oct 2025
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
CVE-2025-59291
HIGH
14 Oct 2025
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
CVE-2025-59290
HIGH
14 Oct 2025
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2025-59288
MEDIUM
14 Oct 2025
Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2025-59284
LOW
14 Oct 2025
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
CVE-2025-59282
HIGH
14 Oct 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVE-2025-59281
HIGH
14 Oct 2025
Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally.
CVE-2025-47979
MEDIUM
14 Oct 2025
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
Page 178 of 687
Page 178 of 687