Filtered by vendor Microsoft Subscriptions
Filtered by product Windows Subscriptions
Total 8778 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-48982 2 Microsoft, Veeam 4 Windows, Agent, Veeam and 1 more 2025-11-01 N/A
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.
CVE-2020-5741 2 Microsoft, Plex 2 Windows, Media Server 2025-11-01 7.2 High
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
CVE-2025-34028 3 Commvault, Linux, Microsoft 3 Commvault, Linux Kernel, Windows 2025-11-01 10 Critical
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.
CVE-2025-3928 3 Commvault, Linux, Microsoft 3 Commvault, Linux Kernel, Windows 2025-11-01 8.8 High
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
CVE-2025-59289 1 Microsoft 13 Windows, Windows 10, Windows 10 21h2 and 10 more 2025-10-31 7 High
Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
CVE-2025-59278 1 Microsoft 19 Windows, Windows 10, Windows 10 1507 and 16 more 2025-10-31 7.8 High
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
CVE-2025-59275 1 Microsoft 19 Windows, Windows 10, Windows 10 1507 and 16 more 2025-10-31 7.8 High
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
CVE-2025-59261 1 Microsoft 11 Graphics Component, Windows, Windows 11 and 8 more 2025-10-31 7 High
Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-59253 1 Microsoft 20 Windows, Windows 10, Windows 10 1507 and 17 more 2025-10-31 5.5 Medium
Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
CVE-2025-59230 1 Microsoft 21 Remote, Windows, Windows 10 and 18 more 2025-10-31 7.8 High
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
CVE-2025-59244 1 Microsoft 20 Windows, Windows 10, Windows 10 1507 and 17 more 2025-10-31 6.5 Medium
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-59241 1 Microsoft 4 Windows, Windows 11, Windows 11 24h2 and 1 more 2025-10-31 7.8 High
Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allows an authorized attacker to elevate privileges locally.
CVE-2025-59214 1 Microsoft 20 Windows, Windows 10, Windows 10 1507 and 17 more 2025-10-31 6.5 Medium
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-59210 1 Microsoft 6 Windows, Windows 11, Windows 11 24h2 and 3 more 2025-10-31 7.4 High
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
CVE-2025-59209 1 Microsoft 19 Windows, Windows 10, Windows 10 1507 and 16 more 2025-10-31 5.5 Medium
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
CVE-2025-59208 1 Microsoft 20 Windows, Windows 10, Windows 10 1507 and 17 more 2025-10-31 7.1 High
Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.
CVE-2025-59205 1 Microsoft 21 Graphics Component, Windows, Windows 10 and 18 more 2025-10-31 7 High
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2025-59203 1 Microsoft 18 Windows, Windows 10, Windows 10 1507 and 15 more 2025-10-31 5.5 Medium
Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.
CVE-2025-59198 1 Microsoft 21 Windows, Windows 10, Windows 10 1507 and 18 more 2025-10-31 5 Medium
Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
CVE-2025-59197 1 Microsoft 18 Windows, Windows 10, Windows 10 1507 and 15 more 2025-10-31 5.5 Medium
Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.