CVE-2025-54095
- EPSS 0.06%
- Published 09.09.2025 17:00:45
- Last modified 02.10.2025 16:36:20
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-53798
- EPSS 0.06%
- Published 09.09.2025 17:00:44
- Last modified 02.10.2025 18:50:29
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-53797
- EPSS 0.06%
- Published 09.09.2025 17:00:43
- Last modified 02.10.2025 18:45:20
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- EPSS 0.04%
- Published 09.09.2025 17:00:41
- Last modified 02.10.2025 18:45:04
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2025-59033
- EPSS 0.04%
- Published 08.09.2025 00:00:00
- Last modified 08.09.2025 18:15:34
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. On systems that do not have hypervisor-protected code integrity (HVCI) enabled, entries that specify only the to-be-signed (TBS) part of ...
CVE-2025-55229
- EPSS 0.04%
- Published 21.08.2025 19:50:40
- Last modified 30.09.2025 18:38:18
Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-55231
- EPSS 0.06%
- Published 21.08.2025 19:50:40
- Last modified 22.08.2025 18:08:51
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network.
CVE-2025-55230
- EPSS 0.06%
- Published 21.08.2025 19:49:44
- Last modified 30.09.2025 18:40:10
Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
CVE-2025-48807
- EPSS 0.05%
- Published 12.08.2025 17:10:44
- Last modified 21.08.2025 20:15:33
Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.
CVE-2025-53789
- EPSS 0.05%
- Published 12.08.2025 17:10:42
- Last modified 14.08.2025 17:11:21
Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.