Latest CVE Feed
- 
                                
                                7.0HIGHCVE-2025-59196Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.... Read more Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +11 more products- Published: Oct. 14, 2025
- Modified: Oct. 30, 2025
 
- 
                                
                                7.0HIGHCVE-2025-23282NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, den... Read more - Published: Oct. 10, 2025
- Modified: Oct. 14, 2025
- Vuln Type: Race Condition
 
- 
                                
                                7.0HIGHCVE-2025-55684Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.... Read more - Published: Oct. 14, 2025
- Modified: Oct. 27, 2025
 
- 
                                
                                7.0HIGHCVE-2025-47989Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.... Read more - Published: Oct. 14, 2025
- Modified: Oct. 20, 2025
 
- 
                                
                                7.0HIGHCVE-2025-34500Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them with a single hard-coded AES key shared across devices, and uses a truncated HMAC for integrity validation. Attackers with access to the u... Read more Affected Products :- Published: Oct. 24, 2025
- Modified: Oct. 27, 2025
- Vuln Type: Cryptography
 
- 
                                
                                7.0HIGHCVE-2025-34503Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker with physical access can replace or reflash the EEPROM to run arbitrary code that persists across reboots. Because this design predates... Read more Affected Products :- Published: Oct. 24, 2025
- Modified: Oct. 27, 2025
- Vuln Type: Authentication
 
- 
                                
                                7.0HIGHCVE-2025-55690Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.... Read more - Published: Oct. 14, 2025
- Modified: Oct. 30, 2025
 
- 
                                
                                7.0HIGHCVE-2025-58731Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.... Read more - Published: Oct. 14, 2025
- Modified: Oct. 16, 2025
 
- 
                                
                                7.0HIGHCVE-2025-58732Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.... Read more Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Published: Oct. 14, 2025
- Modified: Oct. 16, 2025
 
- 
                                
                                7.0HIGHCVE-2025-7330A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admi... Read more - Published: Oct. 14, 2025
- Modified: Oct. 30, 2025
- Vuln Type: Cross-Site Request Forgery
 
- 
                                
                                7.0HIGHCVE-2025-55691Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.... Read more - Published: Oct. 14, 2025
- Modified: Oct. 30, 2025
 
- 
                                
                                7.0HIGHCVE-2025-34133Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API accepts any authenticated request that contains a JSON field named 'csrf_token' without validating the field’s value; only the presence ... Read more Affected Products :- Published: Oct. 27, 2025
- Modified: Oct. 30, 2025
- Vuln Type: Cross-Site Request Forgery
 
- 
                                
                                7.0HIGHCVE-2025-58734Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.... Read more Affected Products : windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows_11_23h2 +6 more products- Published: Oct. 14, 2025
- Modified: Oct. 16, 2025
 
- 
                                
                                7.0HIGHCVE-2025-50174Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.... Read more - Published: Oct. 14, 2025
- Modified: Oct. 23, 2025
 
- 
                                
                                7.0HIGHCVE-2025-59261Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.... Read more - Published: Oct. 14, 2025
- Modified: Oct. 17, 2025
 
- 
                                
                                7.0HIGHCVE-2025-58738Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.... Read more Affected Products : windows_server_2019 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_10_1507 windows_11_23h2 windows_server_2022_23h2 windows_server_23h2 +4 more products- Published: Oct. 14, 2025
- Modified: Oct. 16, 2025
 
- 
                                
                                7.0HIGHCVE-2025-58733Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.... Read more Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +11 more products- Published: Oct. 14, 2025
- Modified: Oct. 16, 2025
 
- 
                                
                                7.0HIGHCVE-2025-58737Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.... Read more - Published: Oct. 14, 2025
- Modified: Oct. 16, 2025
 
- 
                                
                                7.0HIGHCVE-2025-55331Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.... Read more Affected Products : windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 windows_11_23h2 windows_server_2022_23h2 windows_server_23h2 windows_11_24h2 windows_server_2025 windows_11_25h2 +1 more products- Published: Oct. 14, 2025
- Modified: Oct. 27, 2025
 
- 
                                
                                7.0HIGHCVE-2025-23280NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information ... Read more - Published: Oct. 10, 2025
- Modified: Oct. 14, 2025
- Vuln Type: Memory Corruption
 
 
                         
                         
                         
                                             
                                            