Newest CVEs

IDDescriptionSeverity
CVE-2025-53513The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.
medium
CVE-2025-53512The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contain sensitive information.
medium
CVE-2025-49760External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.
low
CVE-2025-49756Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally.
low
CVE-2025-49753Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
high
CVE-2025-49744Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
high
CVE-2025-49742Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally.
high
CVE-2025-49740Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network.
high
CVE-2025-49739Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
high
CVE-2025-49738Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
high
CVE-2025-49737Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.
high
CVE-2025-49735Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
high
CVE-2025-49733Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
high
CVE-2025-49732Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
high
CVE-2025-49731Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
low
CVE-2025-49730Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.
high
CVE-2025-49729Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
high
CVE-2025-49727Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
high
CVE-2025-49726Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
high
CVE-2025-49725Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
high
CVE-2025-49724Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network.
high
CVE-2025-49723Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.
high
CVE-2025-49722Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network.
medium
CVE-2025-49721Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
high
CVE-2025-49719Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
high
CVE-2025-49718Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.
high
CVE-2025-49717Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
high
CVE-2025-49716Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
high
CVE-2025-49714Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally.
high
CVE-2025-49711Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
CVE-2025-49706Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium
CVE-2025-49705Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
high
CVE-2025-49704Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high
CVE-2025-49703Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high
CVE-2025-49702Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2025-49701Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high
CVE-2025-49700Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high
CVE-2025-49699Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2025-49698Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high
CVE-2025-49697Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2025-49696Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2025-49695Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high
CVE-2025-49694Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
high
CVE-2025-49693Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
high
CVE-2025-49691Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.
high
CVE-2025-49690Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.
high
CVE-2025-49689Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
high
CVE-2025-49688Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
high
CVE-2025-49687Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
high
CVE-2025-49686Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
high