Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2025-04-08 CVE-2025-26628 Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally.
local
low complexity
CWE-522
7.3
2025-04-08 CVE-2025-26639 Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
local
low complexity
CWE-122
7.8
2025-04-08 CVE-2025-26640 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
local
high complexity
CWE-416
7.0
2025-04-08 CVE-2025-26642 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
local
low complexity
CWE-190
7.8
2025-04-08 CVE-2025-26647 Improper input validation in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
network
low complexity
8.8
2025-04-08 CVE-2025-26649 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.
local
high complexity
CWE-416
7.0
2025-04-08 CVE-2025-26652 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
network
low complexity
CWE-400
7.5
2025-04-08 CVE-2025-26666 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
local
low complexity
CWE-122
7.8
2025-04-08 CVE-2025-26671 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
network
high complexity
CWE-591
8.1
2025-04-08 CVE-2025-26674 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
local
low complexity
CWE-122
7.8