CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 2h ago | 6.8 | Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
| 2h ago | 6.8 | Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack. |
| 2h ago | 4.4 | Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally. |
| 2h ago | 5.9 | Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. |
| 2h ago | 6.5 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. |
| 2h ago | 5 | Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally. |
| 2h ago | 6.5 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. |
| 2h ago | 6.5 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. |
| 2h ago | 5.5 | Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally. |
| 2h ago | 5.5 | Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally. |
| 2h ago | 6.5 | Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. |
| 2h ago | 6.7 | Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. |
| 2h ago | 6.4 | Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally. |
| 2h ago | 5.5 | Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally. |
| 2h ago | 6.5 | Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network. |
| 2h ago | 6.5 | Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network. |
| 2h ago | 6.5 | Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. |
| 2h ago | 5.5 | Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. |
| 2h ago | 6.7 | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. |
| 2h ago | 4.7 | Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally. |
| 2h ago | 6.7 | Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally. |
| 2h ago | 6.8 | Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. |
| 2h ago | 6.8 | Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. |
| 2h ago | 6.8 | Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack. |
| 2h ago | 5.5 | Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally. |
| 2h ago | 6.7 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. |
| 2h ago | 6.4 | Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally. |
| 2h ago | 6.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
| 2h ago | 6.4 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally. |
| 2h ago | 5.3 | Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network. |