Latest CVE Feed
Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.