Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

CVE-2025-32707

Description: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

CVSS: HIGH (7.8)

EPSS Score: 0.06%

Source: CVE
May 13th, 2025 (25 days ago)

CVE-2025-32706

🚨 Marked as known exploited on May 13th, 2025 (25 days ago).
Description: Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS: HIGH (7.8)

EPSS Score: 10.51%

Source: CVE
May 13th, 2025 (25 days ago)

CVE-2025-32705

Description: Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

CVSS: HIGH (7.8)

EPSS Score: 0.06%

Source: CVE
May 13th, 2025 (25 days ago)

CVE-2025-32704

Description: Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS: HIGH (8.4)

EPSS Score: 0.05%

Source: CVE
May 13th, 2025 (25 days ago)

CVE-2025-32703

Description: Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.

CVSS: MEDIUM (5.5)

EPSS Score: 0.04%

Source: CVE
May 13th, 2025 (25 days ago)

CVE-2025-32702

Description: Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.

CVSS: HIGH (7.8)

EPSS Score: 0.05%

Source: CVE
May 13th, 2025 (25 days ago)

CVE-2025-32701

🚨 Marked as known exploited on May 13th, 2025 (25 days ago).
Description: Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS: HIGH (7.8)

EPSS Score: 4.24%

Source: CVE
May 13th, 2025 (25 days ago)

CVE-2025-30400

🚨 Marked as known exploited on May 13th, 2025 (25 days ago).
Description: Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

CVSS: HIGH (7.8)

EPSS Score: 4.24%

Source: CVE
May 13th, 2025 (25 days ago)

CVE-2025-30397

🚨 Marked as known exploited on May 13th, 2025 (25 days ago).
Description: Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

CVSS: HIGH (7.5)

EPSS Score: 30.91%

Source: CVE
May 13th, 2025 (25 days ago)

CVE-2025-30394

Description: Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

CVSS: MEDIUM (5.9)

EPSS Score: 0.07%

Source: CVE
May 13th, 2025 (25 days ago)