Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.0
Published
2025-08-12
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.8
EPSS Score
0.001
Published
2025-08-12
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.001
Published
2025-08-12
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVSS Score
9.8
EPSS Score
0.001
Published
2025-08-12
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
CVSS Score
5.5
EPSS Score
0.001
Published
2025-08-12
Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.
CVSS Score
8.8
EPSS Score
0.005
Published
2025-08-12
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.004
Published
2025-08-12
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.001
Published
2025-08-12
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS Score
8.4
EPSS Score
0.0
Published
2025-08-12
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.001
Published
2025-08-12


Contact Us

Shodan ® - All rights reserved