threat
engine
.sh
Back
·
··:··
Home
/
Product
/
microsoft windows server 2008
Product
microsoft windows server 2008
500 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-20940
all versions
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-20936
all versions
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
4.3
MEDIUM
CVE-2026-20931
all versions
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adj
8.0
HIGH
CVE-2026-20929
all versions
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
7.5
HIGH
CVE-2026-20927
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an author
5.3
MEDIUM
CVE-2026-20925
all versions
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
6.5
MEDIUM
CVE-2026-20922
all versions
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
7.8
HIGH
CVE-2026-20921
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an author
7.5
HIGH
CVE-2026-20875
all versions
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny ser
7.5
HIGH
CVE-2026-20872
all versions
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
6.5
MEDIUM
CVE-2026-20869
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM)
7.0
HIGH
CVE-2026-20868
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2026-20860
all versions
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorize
7.8
HIGH
CVE-2026-20849
all versions
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a
7.5
HIGH
CVE-2026-20847
all versions
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over
6.5
MEDIUM
CVE-2026-20843
all versions
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges lo
7.8
HIGH
CVE-2026-20840
all versions
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
7.8
HIGH
CVE-2026-20839
all versions
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally
5.5
MEDIUM
CVE-2026-20834
all versions
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
4.6
MEDIUM
CVE-2026-20833
all versions
Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally
5.5
MEDIUM
CVE-2026-20831
all versions
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker t
7.8
HIGH
CVE-2026-20828
all versions
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a phy
4.6
MEDIUM
CVE-2026-20821
all versions
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to dis
6.2
MEDIUM
CVE-2026-20820
all versions
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2026-20816
all versions
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally
7.8
HIGH
CVE-2026-0386
all versions
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
7.5
HIGH
CVE-2025-64678
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-62571
all versions
Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62549
all versions
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code
8.8
HIGH
CVE-2025-62474
all versions
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62473
all versions
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-62472
all versions
Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges loca
7.8
HIGH
CVE-2025-62470
all versions
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62466
all versions
Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62458
all versions
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-62455
all versions
Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-54100
all versions
Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized a
7.8
HIGH
CVE-2025-62452
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over
8.0
HIGH
CVE-2025-62217
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver f
7.0
HIGH
CVE-2025-62213
all versions
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-60724
all versions
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
9.8
CRITICAL
CVE-2025-60720
all versions
Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-60719
all versions
Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges
7.0
HIGH
CVE-2025-60715
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over
8.0
HIGH
CVE-2025-60714
all versions
Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-60709
all versions
Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-60705
all versions
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-60704
all versions
Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
7.5
HIGH
CVE-2025-60703
all versions
Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59514
all versions
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59513
all versions
Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-59295
all versions
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-59282
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unautho
7.0
HIGH
CVE-2025-59280
all versions
Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
3.1
LOW
CVE-2025-59278
all versions
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileg
7.8
HIGH
CVE-2025-59277
all versions
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileg
7.8
HIGH
CVE-2025-59275
all versions
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileg
7.8
HIGH
CVE-2025-59242
all versions
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges lo
7.8
HIGH
CVE-2025-59230
all versions
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59214
all versions
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spo
6.5
MEDIUM
CVE-2025-59208
all versions
Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.
7.1
HIGH
CVE-2025-59205
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows
7.0
HIGH
CVE-2025-59201
all versions
Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-59198
all versions
Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
5.0
MEDIUM
CVE-2025-59196
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an auth
7.0
HIGH
CVE-2025-59190
all versions
Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
5.5
MEDIUM
CVE-2025-59187
all versions
Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-58739
all versions
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spo
6.5
MEDIUM
CVE-2025-58736
all versions
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58735
all versions
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58733
all versions
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58732
all versions
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58730
all versions
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
7.0
HIGH
CVE-2025-58729
all versions
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny servic
6.5
MEDIUM
CVE-2025-58726
all versions
Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
7.5
HIGH
CVE-2025-58725
all versions
Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-58718
all versions
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-58717
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-58714
all versions
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges local
7.8
HIGH
CVE-2025-55701
all versions
Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-55700
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-55695
all versions
Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-55678
all versions
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-55335
all versions
Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
7.4
HIGH
CVE-2025-25004
all versions
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
7.3
HIGH
CVE-2025-24990
all versions
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating s
7.8
HIGH
CVE-2025-24052
all versions
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating s
7.8
HIGH
CVE-2025-55234
all versions
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vuln
8.8
HIGH
CVE-2025-55226
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorize
6.7
MEDIUM
CVE-2025-55225
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-54918
all versions
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
8.8
HIGH
CVE-2025-54917
all versions
Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
4.3
MEDIUM
CVE-2025-54916
all versions
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
7.8
HIGH
CVE-2025-54915
all versions
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker t
6.7
MEDIUM
CVE-2025-54912
all versions
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-54911
all versions
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
7.3
HIGH
CVE-2025-54895
all versions
Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-54894
all versions
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2025-54113
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-54110
all versions
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
8.8
HIGH
CVE-2025-54109
all versions
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker t
6.7
MEDIUM
CVE-2025-54107
all versions
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over
4.3
MEDIUM
CVE-2025-54104
all versions
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker t
6.7
MEDIUM
CVE-2025-54099
all versions
Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges l
7.0
HIGH
CVE-2025-54098
all versions
Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-54097
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-54096
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-54095
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-54094
all versions
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker t
6.7
MEDIUM
CVE-2025-54093
all versions
Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-53810
all versions
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker t
6.7
MEDIUM
CVE-2025-53808
all versions
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker t
6.7
MEDIUM
CVE-2025-53806
all versions
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-53799
all versions
Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-53798
all versions
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-53797
all versions
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-53796
all versions
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-55230
all versions
Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-53778
all versions
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
8.8
HIGH
CVE-2025-53766
all versions
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
9.8
CRITICAL
CVE-2025-53722
all versions
Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a networ
7.5
HIGH
CVE-2025-53720
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over
8.0
HIGH
CVE-2025-53719
all versions
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose inform
5.7
MEDIUM
CVE-2025-53718
all versions
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-53154
all versions
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
7.8
HIGH
CVE-2025-53153
all versions
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose inform
5.7
MEDIUM
CVE-2025-53152
all versions
Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally.
7.8
HIGH
CVE-2025-53149
all versions
Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locall
7.8
HIGH
CVE-2025-53148
all versions
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose inform
5.7
MEDIUM
CVE-2025-53147
all versions
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-53145
all versions
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute
8.8
HIGH
CVE-2025-53144
all versions
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute
8.8
HIGH
CVE-2025-53143
all versions
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute
8.8
HIGH
CVE-2025-53141
all versions
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
7.8
HIGH
CVE-2025-53140
all versions
Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-53138
all versions
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose inform
5.7
MEDIUM
CVE-2025-53137
all versions
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-53136
all versions
Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disclose infor
5.5
MEDIUM
CVE-2025-53134
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver f
7.0
HIGH
CVE-2025-53132
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an aut
7.8
HIGH
CVE-2025-50177
all versions
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
8.1
HIGH
CVE-2025-50173
all versions
Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-50166
all versions
Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose informatio
6.5
MEDIUM
CVE-2025-50164
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over
8.0
HIGH
CVE-2025-50163
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-50162
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over
8.0
HIGH
CVE-2025-50161
all versions
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
7.3
HIGH
CVE-2025-50160
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over
8.0
HIGH
CVE-2025-50158
all versions
Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally.
7.0
HIGH
CVE-2025-50157
all versions
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose inform
5.7
MEDIUM
CVE-2025-50156
all versions
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose inform
5.7
MEDIUM
CVE-2025-50154
all versions
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spo
6.5
MEDIUM
CVE-2025-50153
all versions
Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-49762
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver f
7.0
HIGH
CVE-2025-49761
all versions
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-49757
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-49743
all versions
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows
6.7
MEDIUM
CVE-2025-49753
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-49742
all versions
Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally.
7.8
HIGH
CVE-2025-49732
all versions
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-49730
all versions
Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate priv
7.8
HIGH
CVE-2025-49729
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-49727
all versions
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-49722
all versions
Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjace
5.7
MEDIUM
CVE-2025-49721
all versions
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-49716
all versions
Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
7.5
HIGH
CVE-2025-49689
all versions
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-49686
all versions
Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-49683
all versions
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-49681
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-49679
all versions
Numeric truncation error in Windows Shell allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-49678
all versions
Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-49676
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-49675
all versions
Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-49674
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-49673
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-49672
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-49671
all versions
Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthori
6.5
MEDIUM
CVE-2025-49670
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
6.5
MEDIUM
CVE-2025-49669
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-49668
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-49667
all versions
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-49664
all versions
Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authorized attacke
5.5
MEDIUM
CVE-2025-49663
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-49661
all versions
Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges
7.8
HIGH
CVE-2025-49659
all versions
Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-49658
all versions
Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-49657
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-48824
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-48821
all versions
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an a
7.1
HIGH
CVE-2025-48819
all versions
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized atta
7.1
HIGH
CVE-2025-48817
all versions
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-48816
all versions
Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-48815
all versions
Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to elevate pri
7.8
HIGH
CVE-2025-48814
all versions
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass
7.5
HIGH
CVE-2025-48808
all versions
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information
5.5
MEDIUM
CVE-2025-48806
all versions
Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.
7.8
HIGH
CVE-2025-48805
all versions
Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.
7.8
HIGH
CVE-2025-47998
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-47996
all versions
Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally
7.8
HIGH
CVE-2025-47987
all versions
Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-47986
all versions
Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
8.8
HIGH
CVE-2025-47985
all versions
Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-47984
all versions
Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.
7.5
HIGH
CVE-2025-47981
all versions
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.
9.8
CRITICAL
CVE-2025-47980
all versions
Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclos
6.2
MEDIUM
CVE-2025-47976
all versions
Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-47975
all versions
Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-47973
all versions
Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-47971
all versions
Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-47955
all versions
Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges loca
7.8
HIGH
CVE-2025-33075
all versions
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privi
7.8
HIGH
CVE-2025-33073
all versions
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
8.8
HIGH
CVE-2025-33070
all versions
Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
8.1
HIGH
CVE-2025-33066
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-33064
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over
8.8
HIGH
CVE-2025-33057
all versions
Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.
6.5
MEDIUM
CVE-2025-33056
all versions
Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over
7.5
HIGH
CVE-2025-33053
all versions
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-32724
all versions
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to
7.5
HIGH
CVE-2025-32716
all versions
Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-32715
all versions
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
6.5
MEDIUM
CVE-2025-32714
all versions
Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-32713
all versions
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-32712
all versions
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-32710
all versions
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
8.1
HIGH
CVE-2025-32709
all versions
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
7.8
HIGH
CVE-2025-32707
all versions
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-32706
all versions
Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-32701
all versions
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-30397
all versions
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to exe
7.5
HIGH
CVE-2025-30388
all versions
Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-30385
all versions
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-29974
all versions
Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent
5.7
MEDIUM
CVE-2025-29969
all versions
Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a net
7.5
HIGH
CVE-2025-29968
all versions
Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a ne
6.5
MEDIUM
CVE-2025-29967
all versions
Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-29966
all versions
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-29962
all versions
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-29961
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-29960
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-29959
all versions
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose info
6.5
MEDIUM
CVE-2025-29958
all versions
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose info
6.5
MEDIUM
CVE-2025-29957
all versions
Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.
6.2
MEDIUM
CVE-2025-29956
all versions
Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
5.4
MEDIUM
CVE-2025-29954
all versions
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny
5.9
MEDIUM
CVE-2025-29839
all versions
Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
4.0
MEDIUM
CVE-2025-29837
all versions
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose info
5.5
MEDIUM
CVE-2025-29836
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-29835
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-29832
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
6.5
MEDIUM
CVE-2025-29831
all versions
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
7.5
HIGH
CVE-2025-29830
all versions
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose info
6.5
MEDIUM
CVE-2025-24063
all versions
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-29824
all versions
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-29810
<= -
Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
7.5
HIGH
CVE-2025-27742
all versions
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-27741
all versions
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-27740
all versions
Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a ne
8.8
HIGH
CVE-2025-27737
all versions
Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.
8.6
HIGH
CVE-2025-27733
all versions
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-27732
all versions
Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges lo
7.0
HIGH
CVE-2025-27727
all versions
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privi
7.8
HIGH
CVE-2025-27487
all versions
Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
8.0
HIGH
CVE-2025-27484
all versions
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized atta
7.5
HIGH
CVE-2025-27481
all versions
Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-27478
all versions
Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-27477
all versions
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-27474
all versions
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose info
6.5
MEDIUM
CVE-2025-27473
all versions
Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
7.5
HIGH
CVE-2025-27471
all versions
Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service
5.9
MEDIUM
CVE-2025-27469
all versions
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny
7.5
HIGH
CVE-2025-26687
all versions
Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.
7.5
HIGH
CVE-2025-26686
all versions
Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a networ
7.5
HIGH
CVE-2025-26679
all versions
Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-26676
all versions
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-26673
all versions
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny
7.5
HIGH
CVE-2025-26672
all versions
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-26671
all versions
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
8.1
HIGH
CVE-2025-26670
all versions
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a netw
8.1
HIGH
CVE-2025-26669
all versions
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information ove
8.8
HIGH
CVE-2025-26668
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
7.5
HIGH
CVE-2025-26667
all versions
Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthori
6.5
MEDIUM
CVE-2025-26665
all versions
Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges loc
7.0
HIGH
CVE-2025-26664
all versions
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-26663
all versions
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a netw
8.1
HIGH
CVE-2025-26648
all versions
Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-26647
all versions
Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
8.8
HIGH
CVE-2025-26641
all versions
Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network
7.5
HIGH
CVE-2025-21222
all versions
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-21221
all versions
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-21205
all versions
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-21204
all versions
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate pr
7.8
HIGH
CVE-2025-21203
all versions
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over
6.5
MEDIUM
CVE-2025-21197
all versions
Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the a
6.5
MEDIUM
CVE-2025-21191
all versions
Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to eleva
7.0
HIGH
CVE-2025-26645
all versions
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-26633
all versions
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
7.0
HIGH
CVE-2025-24996
all versions
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
6.5
MEDIUM
CVE-2025-24993
all versions
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-24992
all versions
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-24991
all versions
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
5.5
MEDIUM
CVE-2025-24988
all versions
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.
6.6
MEDIUM
CVE-2025-24987
all versions
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.
6.6
MEDIUM
CVE-2025-24985
all versions
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-24983
all versions
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
7.0
HIGH
CVE-2025-24072
all versions
Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-24064
all versions
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
8.1
HIGH
CVE-2025-24059
all versions
Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privi
7.8
HIGH
CVE-2025-24056
all versions
Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-24055
all versions
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.
4.3
MEDIUM
CVE-2025-24054
all versions
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
6.5
MEDIUM
CVE-2025-24051
all versions
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code ove
8.8
HIGH
CVE-2025-24035
all versions
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute c
8.1
HIGH
CVE-2025-21247
all versions
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over
4.3
MEDIUM
CVE-2025-21180
all versions
Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-21419
all versions
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
7.1
HIGH
CVE-2025-21418
all versions
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2025-21410
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21407
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21406
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21377
all versions
NTLM Hash Disclosure Spoofing Vulnerability
6.5
MEDIUM
CVE-2025-21376
all versions
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
8.1
HIGH
CVE-2025-21375
all versions
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2025-21373
all versions
Windows Installer Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2025-21371
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21369
all versions
Microsoft Digest Authentication Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21368
all versions
Microsoft Digest Authentication Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21359
all versions
Windows Kernel Security Feature Bypass Vulnerability
7.8
HIGH
CVE-2025-21352
all versions
Internet Connection Sharing (ICS) Denial of Service Vulnerability
6.5
MEDIUM
CVE-2025-21350
all versions
Windows Kerberos Denial of Service Vulnerability
5.9
MEDIUM
CVE-2025-21337
all versions
Windows NTFS Elevation of Privilege Vulnerability
3.3
LOW
CVE-2025-21208
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21201
all versions
Windows Telephony Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21200
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21190
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21181
all versions
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
7.5
HIGH
CVE-2025-21417
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21413
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21411
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21409
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21389
all versions
Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny se
7.5
HIGH
CVE-2025-21341
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21339
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21338
all versions
GDI+ Remote Code Execution Vulnerability
7.8
HIGH
CVE-2025-21336
all versions
Windows Cryptographic Information Disclosure Vulnerability
5.6
MEDIUM
CVE-2025-21332
all versions
MapUrlToZone Security Feature Bypass Vulnerability
4.3
MEDIUM
CVE-2025-21331
all versions
Windows Installer Elevation of Privilege Vulnerability
7.3
HIGH
CVE-2025-21329
all versions
MapUrlToZone Security Feature Bypass Vulnerability
4.3
MEDIUM
CVE-2025-21328
all versions
MapUrlToZone Security Feature Bypass Vulnerability
4.3
MEDIUM
CVE-2025-21327
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21324
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21320
all versions
Windows Kernel Memory Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2025-21319
all versions
Windows Kernel Memory Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2025-21310
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21307
all versions
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2025-21306
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21305
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21303
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21302
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21300
all versions
Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
7.5
HIGH
CVE-2025-21298
all versions
Windows OLE Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2025-21297
all versions
Windows Remote Desktop Services Remote Code Execution Vulnerability
8.1
HIGH
CVE-2025-21296
all versions
BranchCache Remote Code Execution Vulnerability
7.5
HIGH
CVE-2025-21295
all versions
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
8.1
HIGH
CVE-2025-21294
all versions
Microsoft Digest Authentication Remote Code Execution Vulnerability
8.1
HIGH
CVE-2025-21290
all versions
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
7.5
HIGH
CVE-2025-21289
all versions
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
7.5
HIGH
CVE-2025-21288
all versions
Windows COM Server Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2025-21287
all versions
Windows Installer Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2025-21286
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21285
all versions
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
7.5
HIGH
CVE-2025-21282
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21277
all versions
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
7.5
HIGH
CVE-2025-21276
all versions
Windows MapUrlToZone Denial of Service Vulnerability
7.5
HIGH
CVE-2025-21273
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21272
all versions
Windows COM Server Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2025-21270
all versions
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
7.5
HIGH
CVE-2025-21269
all versions
Windows HTML Platforms Security Feature Bypass Vulnerability
4.3
MEDIUM
CVE-2025-21268
all versions
MapUrlToZone Security Feature Bypass Vulnerability
4.3
MEDIUM
CVE-2025-21266
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21265
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21263
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21261
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21260
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21258
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21256
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21255
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21252
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21251
all versions
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
7.5
HIGH
CVE-2025-21250
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21249
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21246
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21245
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21244
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21243
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21242
all versions
Windows Kerberos Information Disclosure Vulnerability
5.9
MEDIUM
CVE-2025-21240
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21238
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21237
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21236
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21233
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21232
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21231
all versions
IP Helper Denial of Service Vulnerability
7.5
HIGH
CVE-2025-21230
all versions
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
7.5
HIGH
CVE-2025-21228
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21227
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21226
all versions
Windows Digital Media Elevation of Privilege Vulnerability
6.6
MEDIUM
CVE-2025-21223
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2025-21220
all versions
Microsoft Message Queuing Information Disclosure Vulnerability
7.5
HIGH
CVE-2025-21217
all versions
Windows NTLM Spoofing Vulnerability
6.5
MEDIUM
CVE-2025-21215
all versions
Secure Boot Security Feature Bypass Vulnerability
4.6
MEDIUM
CVE-2025-21214
all versions
Windows BitLocker Information Disclosure Vulnerability
4.2
MEDIUM
CVE-2025-21210
all versions
Windows BitLocker Information Disclosure Vulnerability
4.2
MEDIUM
CVE-2025-21189
all versions
MapUrlToZone Security Feature Bypass Vulnerability
4.3
MEDIUM
CVE-2024-49138
all versions
Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-49127
all versions
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
8.1
HIGH
CVE-2024-49126
all versions
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
8.1
HIGH
CVE-2024-49125
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-49124
all versions
Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
8.1
HIGH
CVE-2024-49122
all versions
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
8.1
HIGH
CVE-2024-49121
all versions
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
7.5
HIGH
CVE-2024-49118
all versions
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
8.1
HIGH
CVE-2024-49113
all versions
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
7.5
HIGH
CVE-2024-49112
all versions
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2024-49105
all versions
Remote Desktop Client Remote Code Execution Vulnerability
8.4
HIGH
CVE-2024-49104
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-49102
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-49096
all versions
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
7.5
HIGH
CVE-2024-49090
all versions
Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-49089
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
7.2
HIGH
CVE-2024-49088
all versions
Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-49086
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-49085
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-49084
all versions
Windows Kernel Elevation of Privilege Vulnerability
7.0
HIGH
CVE-2024-49082
all versions
Windows File Explorer Information Disclosure Vulnerability
6.8
MEDIUM
CVE-2024-49080
all versions
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-49072
all versions
Windows Task Scheduler Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-49046
all versions
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-49019
all versions
Active Directory Certificate Services Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-43644
all versions
Windows Client-Side Caching Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-43643
all versions
Windows USB Video Class System Driver Elevation of Privilege Vulnerability
6.8
MEDIUM
CVE-2024-43641
all versions
Windows Registry Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-43638
all versions
Windows USB Video Class System Driver Elevation of Privilege Vulnerability
6.8
MEDIUM
CVE-2024-43637
all versions
Windows USB Video Class System Driver Elevation of Privilege Vulnerability
6.8
MEDIUM
CVE-2024-43635
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43634
all versions
Windows USB Video Class System Driver Elevation of Privilege Vulnerability
6.8
MEDIUM
CVE-2024-43628
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43627
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43626
all versions
Windows Telephony Service Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-43623
all versions
Windows NT OS Kernel Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-43622
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43621
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43620
all versions
Windows Telephony Service Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43452
all versions
Windows Registry Elevation of Privilege Vulnerability
7.5
HIGH
CVE-2024-43451
all versions
NTLM Hash Disclosure Spoofing Vulnerability
6.5
MEDIUM
CVE-2024-43450
all versions
Windows DNS Spoofing Vulnerability
7.5
HIGH
CVE-2024-43449
all versions
Windows USB Video Class System Driver Elevation of Privilege Vulnerability
6.8
MEDIUM
CVE-2024-38203
all versions
Windows Package Library Manager Information Disclosure Vulnerability
6.2
MEDIUM
CVE-2024-43611
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43608
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43607
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43599
all versions
Remote Desktop Client Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43593
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43592
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43589
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43583
all versions
Winlogon Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-43572
all versions
Microsoft Management Console Remote Code Execution Vulnerability
7.8
HIGH
CVE-2024-43570
all versions
Windows Kernel Elevation of Privilege Vulnerability
6.4
MEDIUM
CVE-2024-43564
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43556
all versions
Windows Graphics Component Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-43553
all versions
NT OS Kernel Elevation of Privilege Vulnerability
7.4
HIGH
CVE-2024-43549
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43547
all versions
Windows Kerberos Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2024-43545
all versions
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
7.5
HIGH
CVE-2024-43544
all versions
Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
7.5
HIGH
CVE-2024-43541
all versions
Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
7.5
HIGH
CVE-2024-43535
all versions
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
7.0
HIGH
CVE-2024-43534
all versions
Windows Graphics Component Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2024-43532
all versions
Remote Registry Service Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2024-43520
all versions
Windows Kernel Denial of Service Vulnerability
5.0
MEDIUM
CVE-2024-43519
all versions
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43518
all versions
Windows Telephony Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43517
all versions
Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-43515
all versions
Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability
7.5
HIGH
CVE-2024-43509
all versions
Windows Graphics Component Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-43506
all versions
BranchCache Denial of Service Vulnerability
7.5
HIGH
CVE-2024-43501
all versions
Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8
HIGH
CVE-2024-43456
all versions
Windows Remote Desktop Services Tampering Vulnerability
4.8
MEDIUM
CVE-2024-43453
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-38265
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-38262
all versions
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
7.5
HIGH
CVE-2024-38261
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
7.8
HIGH
CVE-2024-38212
all versions
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
8.8
HIGH
CVE-2024-38149
all versions
BranchCache Denial of Service Vulnerability
7.5
HIGH
CVE-2024-38124
all versions
Windows Netlogon Elevation of Privilege Vulnerability
9.0
CRITICAL
CVE-2024-43475
all versions
Microsoft Windows Admin Center Information Disclosure Vulnerability
7.3
HIGH
CVE-2024-43467
all versions
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
7.5
HIGH
CVE-2024-43461
all versions
Windows MSHTML Platform Spoofing Vulnerability
8.8
HIGH
CVE-2024-43455
all versions
Windows Remote Desktop Licensing Service Spoofing Vulnerability
8.8
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin