
CVE-2025-30378 – Microsoft SharePoint Server Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2025-30378
13 May 2025 — Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30378 • CWE-502: Deserialization of Untrusted Data •

CVE-2025-30376 – Microsoft Excel Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2025-30376
13 May 2025 — Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30376 • CWE-122: Heap-based Buffer Overflow CWE-125: Out-of-bounds Read •

CVE-2025-30375 – Microsoft Excel Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2025-30375
13 May 2025 — Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-30375 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •

CVE-2025-29979 – Microsoft Excel Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2025-29979
13 May 2025 — Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29979 • CWE-122: Heap-based Buffer Overflow •

CVE-2025-29977 – Microsoft Excel Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2025-29977
13 May 2025 — Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29977 • CWE-416: Use After Free •

CVE-2025-29976 – Microsoft SharePoint Server Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2025-29976
13 May 2025 — Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29976 • CWE-269: Improper Privilege Management •

CVE-2025-29970 – Microsoft Brokering File System Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2025-29970
13 May 2025 — Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29970 • CWE-416: Use After Free •

CVE-2025-29969 – MS-EVEN RPC Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2025-29969
13 May 2025 — Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29969 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •

CVE-2025-29968 – Active Directory Certificate Services (AD CS) Denial of Service Vulnerability
https://notcve.org/view.php?id=CVE-2025-29968
13 May 2025 — Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29968 • CWE-20: Improper Input Validation •

CVE-2025-29967 – Remote Desktop Client Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2025-29967
13 May 2025 — Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29967 • CWE-122: Heap-based Buffer Overflow •