7.8
CVE-2025-32716 - Windows Media Elevation of Privilege Vulnerability
Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.
6.5
CVE-2025-32715 - Remote Desktop Protocol Client Information Disclosure Vulnerability
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
7.8
CVE-2025-32714 - Windows Installer Elevation of Privilege Vulnerability
Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-32713 - Windows Common Log File System Driver Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
7.8
CVE-2025-32712 - Win32k Elevation of Privilege Vulnerability
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
8.1
CVE-2025-32710 - Windows Remote Desktop Services Remote Code Execution Vulnerability
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
8.1
CVE-2025-29828 - Windows Schannel Remote Code Execution Vulnerability
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.
8.4
CVE-2025-47957 - Microsoft Word Remote Code Execution Vulnerability
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
4.8
CVE-2025-5970 - PHPGurukul Restaurant Table Booking System add-subadmin.php cross site scripting
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be launched reβ¦
7.6
CVE-2024-43706 - Kibana Improper Authorization
Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.