CVE-2025-29830
- EPSS 0.37%
- Published 13.05.2025 16:58:56
- Last modified 19.05.2025 18:20:32
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-26677
- EPSS 14.06%
- Published 13.05.2025 16:58:54
- Last modified 19.05.2025 18:23:01
Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.
CVE-2025-32709
- EPSS 1.1%
- Published 13.05.2025 16:58:53
- Last modified 16.05.2025 16:29:34
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2025-32706
- EPSS 1.45%
- Published 13.05.2025 16:58:51
- Last modified 16.09.2025 14:17:38
Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-32701
- EPSS 1.09%
- Published 13.05.2025 16:58:50
- Last modified 16.05.2025 16:25:54
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-30394
- EPSS 0.16%
- Published 13.05.2025 16:58:49
- Last modified 19.05.2025 18:30:32
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.
CVE-2025-30400
- EPSS 1.09%
- Published 13.05.2025 16:58:49
- Last modified 16.05.2025 16:26:11
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
- EPSS 0.08%
- Published 13.05.2025 16:58:47
- Last modified 19.05.2025 18:22:00
Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2025-29969
- EPSS 0.12%
- Published 13.05.2025 16:58:33
- Last modified 19.05.2025 14:20:58
Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.
CVE-2025-29968
- EPSS 0.37%
- Published 13.05.2025 16:58:32
- Last modified 19.05.2025 14:21:08
Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.