Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-27474

Description: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVSS: MEDIUM (6.5)

EPSS Score: 0.17%

Source: CVE
April 8th, 2025 (11 days ago)

CVE-2025-27472

Description: Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

CVSS: MEDIUM (5.4)

EPSS Score: 0.1%

Source: CVE
April 8th, 2025 (11 days ago)

CVE-2025-27471

Description: Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.

CVSS: MEDIUM (5.9)

EPSS Score: 0.05%

Source: CVE
April 8th, 2025 (11 days ago)

CVE-2025-26681

Description: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVSS: MEDIUM (6.7)

EPSS Score: 0.05%

Source: CVE
April 8th, 2025 (11 days ago)

CVE-2025-26676

Description: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVSS: MEDIUM (6.5)

EPSS Score: 0.06%

Source: CVE
April 8th, 2025 (11 days ago)

CVE-2025-26672

Description: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVSS: MEDIUM (6.5)

EPSS Score: 0.06%

Source: CVE
April 8th, 2025 (11 days ago)

CVE-2025-26667

Description: Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVSS: MEDIUM (6.5)

EPSS Score: 0.06%

Source: CVE
April 8th, 2025 (11 days ago)

CVE-2025-26664

Description: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

CVSS: MEDIUM (6.5)

EPSS Score: 0.06%

Source: CVE
April 8th, 2025 (11 days ago)

CVE-2025-26651

Description: Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

CVSS: MEDIUM (6.5)

EPSS Score: 2.48%

Source: CVE
April 8th, 2025 (11 days ago)

CVE-2025-26644

Description: Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.

CVSS: MEDIUM (5.1)

EPSS Score: 0.05%

Source: CVE
April 8th, 2025 (11 days ago)