Common Vulnerabilities and Exposures (CVE)

CVE-2025-55333

Feb 13, 2026 23:11:31 UTC

Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2025-55325

Feb 13, 2026 23:11:30 UTC

Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.

CVE-2025-55320

Feb 13, 2026 23:11:30 UTC

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network.

CVE-2025-24052

Feb 13, 2026 23:11:29 UTC

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed i...

CVE-2025-24990

Feb 13, 2026 23:11:28 UTC

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed i...

CVE-2025-55315

Feb 13, 2026 23:11:28 UTC

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

CVE-2025-55247

Feb 13, 2026 23:11:27 UTC

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.

CVE-2025-53782

Feb 13, 2026 23:11:27 UTC

Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

CVE-2025-50174

Feb 13, 2026 23:11:26 UTC

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

CVE-2025-48004

Feb 13, 2026 23:11:25 UTC

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

CVE-2025-47989

Feb 13, 2026 23:11:24 UTC

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

CVE-2025-67736

Feb 13, 2026 22:12:03 UTC

The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manages Asterisk. Versions prior to 16.0.5 and 17.0.5 are vulnerable to SQL injection by authenticated users with administrato...

CVE-2025-67513

Feb 13, 2026 22:10:39 UTC

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute force...

CVE-2025-9293

Feb 13, 2026 22:10:15 UTC

A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modi...

CVE-2025-66039

Feb 13, 2026 22:09:29 UTC

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an ar...