7.8
CVE-2025-49730 - Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability
Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.
8.8
CVE-2025-49729 - Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
7
CVE-2025-49727 - Win32k Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-49725 - Windows Notification Elevation of Privilege Vulnerability
Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
8.8
CVE-2025-49724 - Windows Connected Devices Platform Service Remote Code Execution Vulnerability
Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network.
5.7
CVE-2025-49722 - Windows Print Spooler Denial of Service Vulnerability
Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network.
7.5
CVE-2025-49718 - Microsoft SQL Server Information Disclosure Vulnerability
Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.
7.8
CVE-2025-49714 - Visual Studio Code Python Extension Remote Code Execution Vulnerability
Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally.
6.5
CVE-2025-49706 - Microsoft SharePoint Server Spoofing Vulnerability
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
7.8
CVE-2025-49705 - Microsoft PowerPoint Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.