9.9
CVE-2025-55315 - ASP.NET Security Feature Bypass Vulnerability
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
7.3
CVE-2025-55247 - .NET Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
8.4
CVE-2025-53782 - Microsoft Exchange Server Elevation of Privilege Vulnerability
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
7
CVE-2025-50174 - Windows Device Association Broker Service Elevation of Privilege Vulnerability
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
7.4
CVE-2025-48004 - Microsoft Brokering File System Elevation of Privilege Vulnerability
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
7
CVE-2025-47989 - Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
4.9
CVE-2025-37142 - Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Coβ¦
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.
4.9
CVE-2025-37141 - Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Coβ¦
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.
4.9
CVE-2025-37140 - Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Coβ¦
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.
6
CVE-2025-37139 - Vulnerability in AOS firmware allows for Authenticated Local malicious actor to Permanently Disableβ¦
A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploitation may render the system unbootable, resulting in a Denial of Service that can only be resolved by replacing the affected hardware.