Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-04-08 CVE-2025-27731 Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.
local
low complexity
CWE-20
7.8
2025-04-08 CVE-2025-27736 Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.
local
low complexity
CWE-200
5.5
2025-04-08 CVE-2025-27739 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
local
low complexity
CWE-822
7.8
2025-04-08 CVE-2025-27740 Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network.
network
low complexity
8.8
2025-04-08 CVE-2025-27743 Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
local
low complexity
CWE-426
7.8
2025-04-08 CVE-2025-27744 Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.
local
low complexity
CWE-284
7.8
2025-04-08 CVE-2025-29792 Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
local
low complexity
CWE-416
7.3
2025-04-08 CVE-2025-29793 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
network
low complexity
CWE-502
7.2
2025-04-08 CVE-2025-29794 Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
network
low complexity
CWE-285
8.8
2025-04-08 CVE-2025-29800 Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
local
low complexity
CWE-269
7.8