High - CVE-2025-48819 - Sensitive data storage in improperly locked...
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
High - CVE-2025-48820 - Improper link resolution before file access...
Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.
NA - CVE-2025-0928 - In Juju versions prior to 3.6.8 and 2.9.52, any...
In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verifying model...