CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 7.8 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7.8 | Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. |
| 1mo ago | 8.8 | Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network. |
| 1mo ago | 7.8 | Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 8.6 | Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally. |
| 1mo ago | 7.8 | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. |
| 1mo ago | 7 | Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Use after free in Windows Shell allows an unauthorized attacker to execute code locally. |
| 1mo ago | 7.8 | Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.1 | Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network. |
| 1mo ago | 7.8 | Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 7.8 | Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 8 | Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. |
| 1mo ago | 7.5 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. |
| 1mo ago | 7.5 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. |
| 1mo ago | 7.5 | Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network. |
| 1mo ago | 7.8 | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. |
| 1mo ago | 8.1 | Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. |
| 1mo ago | 8.8 | Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. |
| 1mo ago | 8.1 | Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. |
| 1mo ago | 7.5 | Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network. |
| 1mo ago | 7 | Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. |
| 1mo ago | 8.8 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. |
| 1mo ago | 7.8 | Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. |