CVE-2026-50508
- EPSS 8.68%
- Published 09.06.2026 17:17:50
- Last modified 23.07.2026 08:10:00
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-64679
- EPSS 0.46%
- Published 09.12.2025 17:56:08
- Last modified 12.12.2025 13:35:37
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-64680
- EPSS 0.37%
- Published 09.12.2025 17:56:08
- Last modified 12.12.2025 13:31:49
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-62209
- EPSS 0.52%
- Published 11.11.2025 18:15:48
- Last modified 17.11.2025 17:40:05
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
CVE-2025-62208
- EPSS 0.52%
- Published 11.11.2025 18:15:47
- Last modified 17.11.2025 17:40:13
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
- EPSS 0.22%
- Published 14.10.2025 17:01:48
- Last modified 22.10.2025 16:45:33
Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2025-59278
- EPSS 0.26%
- Published 14.10.2025 17:01:46
- Last modified 27.10.2025 19:44:49
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
- EPSS 0.18%
- Published 14.10.2025 17:01:45
- Last modified 17.10.2025 15:52:53
Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-59275
- EPSS 0.26%
- Published 14.10.2025 17:01:45
- Last modified 27.10.2025 20:12:00
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
CVE-2025-59230
- EPSS 2.58%
- Published 14.10.2025 17:01:43
- Last modified 03.12.2025 13:47:09
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.