Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-59188 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59186 | Med | 0.36 | 5.5 | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59184 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally. | ||
| CVE-2025-55699 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-55695 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally. | ||
| CVE-2025-55683 | Med | 0.36 | 5.5 | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-55676 | Med | 0.36 | 5.5 | 0.01 | Oct 14, 2025 | Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally. | ||
| CVE-2025-55336 | Med | 0.36 | 5.5 | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally. | ||
| CVE-2025-55325 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-47979 | Med | 0.36 | 5.5 | 0.01 | Oct 14, 2025 | Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally. | ||
| CVE-2025-54901 | Med | 0.36 | 5.5 | 0.01 | Sep 9, 2025 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-53804 | Med | 0.36 | 5.5 | 0.01 | Sep 9, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-53803 | Med | 0.36 | 5.5 | 0.01 | Sep 9, 2025 | Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-53799 | Med | 0.36 | 5.5 | 0.01 | Sep 9, 2025 | Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-53769 | Med | 0.36 | 5.5 | 0.00 | Aug 12, 2025 | External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally. | ||
| CVE-2025-53156 | Med | 0.36 | 5.5 | 0.01 | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally. | ||
| CVE-2025-53136 | Med | 0.36 | 5.5 | 0.01 | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-47182 | Med | 0.36 | 5.6 | 0.00 | Jul 11, 2025 | Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2025-49684 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally. | ||
| CVE-2025-49664 | Med | 0.36 | 5.5 | 0.01 | Jul 8, 2025 | Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authorized attacker to disclose information locally. | ||
| CVE-2025-49658 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally. | ||
| CVE-2025-48812 | Med | 0.36 | 5.5 | 0.01 | Jul 8, 2025 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-48810 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Processor optimization removal or modification of security-critical code in Windows Secure Kernel Mode allows an authorized attacker to disclose information locally. | ||
| CVE-2025-48809 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-48808 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-26636 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-47956 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally. | ||
| CVE-2025-33065 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-33063 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-33062 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-33061 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-33060 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-33059 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-33058 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-33055 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-33052 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally. | ||
| CVE-2025-32722 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally. | ||
| CVE-2025-32720 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-32719 | Med | 0.36 | 5.5 | 0.00 | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-24069 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-24068 | Med | 0.36 | 5.5 | 0.00 | Jun 10, 2025 | Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-24065 | Med | 0.36 | 5.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | ||
| CVE-2025-32703 | Med | 0.36 | 5.5 | 0.00 | May 13, 2025 | Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. | ||
| CVE-2025-29837 | Med | 0.36 | 5.5 | 0.01 | May 13, 2025 | Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally. | ||
| CVE-2025-29829 | Med | 0.36 | 5.5 | 0.01 | May 13, 2025 | Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally. | ||
| CVE-2025-29821 | Med | 0.36 | 5.5 | 0.01 | Apr 8, 2025 | Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally. | ||
| CVE-2025-29808 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | ||
| CVE-2025-27742 | Med | 0.36 | 5.5 | 0.01 | Apr 8, 2025 | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-27736 | Med | 0.36 | 5.5 | 0.01 | Apr 8, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally. | ||
| CVE-2025-21953 | Med | 0.36 | 5.5 | 0.00 | Apr 1, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: mana: cleanup mana struct after debugfs_remove() When on a MANA VM hibernation is triggered, as part of hibernate_snapshot(), mana_gd_suspend() and mana_gd_resume() are called. If during this… |
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.6epss 0.00
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Processor optimization removal or modification of security-critical code in Windows Secure Kernel Mode allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
In the Linux kernel, the following vulnerability has been resolved: net: mana: cleanup mana struct after debugfs_remove() When on a MANA VM hibernation is triggered, as part of hibernate_snapshot(), mana_gd_suspend() and mana_gd_resume() are called. If during this…
Page 186 of 314