| CVE-2025-49752 |
Azure Bastion Elevation of Privilege Vulnerability |
10.0 |
critical |
|
| CVE-2025-40165 |
media: nxp: imx8-isi: m2m: Fix streaming cleanup on release |
9.8 |
critical |
|
| CVE-2025-40172 |
accel/qaic: Treat remaining == 0 as error in find_and_map_user_pages() |
9.8 |
critical |
|
| CVE-2025-59245 |
Microsoft SharePoint Online Elevation of Privilege Vulnerability |
9.8 |
critical |
|
| CVE-2025-64657 |
Azure Application Gateway Elevation of Privilege Vulnerability |
9.8 |
critical |
|
| CVE-2025-64656 |
Azure Application Gateway Elevation of Privilege Vulnerability |
9.4 |
critical |
|
| CVE-2025-64655 |
Dynamics OmniChannel SDK Storage Containers Elevation of Privilege Vulnerability |
8.8 |
critical |
|
| CVE-2025-62207 |
Azure Monitor Elevation of Privilege Vulnerability |
8.6 |
critical |
|
| CVE-2025-62459 |
Microsoft Defender Portal Spoofing Vulnerability |
8.3 |
critical |
|
| CVE-2025-30398 |
Nuance PowerScribe 360 Information Disclosure Vulnerability |
8.1 |
critical |
|
| CVE-2025-62199 |
Microsoft Office Remote Code Execution Vulnerability |
7.8 |
critical |
|
| CVE-2025-60716 |
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
7.0 |
critical |
|
| CVE-2025-62214 |
Visual Studio Remote Code Execution Vulnerability |
6.7 |
critical |
|
| CVE-2025-60724 |
GDI+ Remote Code Execution Vulnerability |
9.8 |
high |
|
| CVE-2025-60876 |
BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). |
9.4 |
high |
|
| CVE-2025-12970 |
CVE-2025-12970 |
8.8 |
high |
|
| CVE-2025-13226 |
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
8.8 |
high |
|
| CVE-2025-59499 |
Microsoft SQL Server Elevation of Privilege Vulnerability |
8.8 |
high |
|
| CVE-2025-62220 |
Windows Subsystem for Linux GUI Remote Code Execution Vulnerability |
8.8 |
high |
|
| CVE-2025-62222 |
Agentic AI and Visual Studio Code Remote Code Execution Vulnerability |
8.8 |
high |
|
| CVE-2025-62210 |
Dynamics 365 Field Service (online) Spoofing Vulnerability |
8.7 |
high |
|
| CVE-2025-62211 |
Dynamics 365 Field Service (online) Spoofing Vulnerability |
8.7 |
high |
|
| CVE-2025-12816 |
CVE-2025-12816 |
8.6 |
high |
|
| CVE-2025-13227 |
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
8.6 |
high |
|
| CVE-2025-13230 |
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
8.6 |
high |
|
| CVE-2025-40135 |
ipv6: use RCU in ip6_xmit() |
8.4 |
high |
|
| CVE-2025-40139 |
smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set(). |
8.4 |
high |
|
| CVE-2025-40176 |
tls: wait for pending async decryptions if tls_strp_msg_hold fails |
8.4 |
high |
|
| CVE-2025-12977 |
CVE-2025-12977 |
8.3 |
high |
|
| CVE-2025-40170 |
net: use dst_dev_rcu() in sk_setup_caps() |
8.1 |
high |
|
| CVE-2025-60715 |
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
8.0 |
high |
|
| CVE-2025-62204 |
Microsoft SharePoint Remote Code Execution Vulnerability |
8.0 |
high |
|
| CVE-2025-62452 |
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
8.0 |
high |
|
| CVE-2025-64660 |
GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability |
8.0 |
high |
|
| CVE-2025-40198 |
ext4: avoid potential buffer over-read in parse_apply_sb_mount_options() |
7.8 |
high |
|
| CVE-2025-40205 |
btrfs: avoid potential out-of-bounds in btrfs_encode_fh() |
7.8 |
high |
|
| CVE-2025-40211 |
ACPI: video: Fix use-after-free in acpi_video_switch_brightness() |
7.8 |
high |
|
| CVE-2025-59505 |
Windows Smart Card Reader Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59511 |
Windows WLAN Service Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59512 |
Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59514 |
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-60703 |
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-60705 |
Windows Client-Side Caching Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-60707 |
Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-60709 |
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-60710 |
Host Process for Windows Tasks Elevation of Privilege Vulnerability |
7.8 |
high |
Yes |
| CVE-2025-60713 |
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-60714 |
Windows OLE Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-60718 |
Windows Administrator Protection Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-60720 |
Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-60721 |
Windows Administrator Protection Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-60727 |
Microsoft Excel Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-62200 |
Microsoft Excel Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-62201 |
Microsoft Excel Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-62203 |
Microsoft Excel Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-62205 |
Microsoft Office Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-62216 |
Microsoft Office Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-13601 |
Glib: integer overflow in in g_escape_uri_string() |
7.7 |
high |
|
| CVE-2025-12638 |
Path Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_file() |
7.6 |
high |
|
| CVE-2024-47866 |
RGW DoS attack with empty HTTP header in S3 object copy |
7.5 |
high |
|
| CVE-2025-12863 |
Libxml2: namespace use-after-free in xmlsettreedoc() function of libxml2 |
7.5 |
high |
|
| CVE-2025-47913 |
Potential denial of service in golang.org/x/crypto/ssh/agent |
7.5 |
high |
|
| CVE-2025-59777 |
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition. |
7.5 |
high |
|
| CVE-2025-62689 |
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition. |
7.5 |
high |
|
| CVE-2025-60704 |
Windows Kerberos Elevation of Privilege Vulnerability |
7.5 |
high |
|
| CVE-2024-25621 |
containerd affected by a local privilege escalation via wide permissions on CRI directory |
7.3 |
high |
|
| CVE-2025-52881 |
runc: LSM labels can be bypassed with malicious config using dummy procfs files |
7.3 |
high |
|
| CVE-2025-59504 |
Azure Monitor Agent Remote Code Execution Vulnerability |
7.3 |
high |
|
| CVE-2025-40190 |
ext4: guard against EA inode refcount underflow in xattr update |
7.1 |
high |
|
| CVE-2025-40201 |
kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths |
7.1 |
high |
|
| CVE-2025-40204 |
sctp: Fix MAC comparison to be constant-time |
7.1 |
high |
|
| CVE-2025-64720 |
LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication |
7.1 |
high |
|
| CVE-2025-65018 |
LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read` |
7.1 |
high |
|
| CVE-2025-60726 |
Microsoft Excel Information Disclosure Vulnerability |
7.1 |
high |
|
| CVE-2025-62202 |
Microsoft Excel Information Disclosure Vulnerability |
7.1 |
high |
|
| CVE-2025-59506 |
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2025-59507 |
Windows Speech Runtime Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2025-59508 |
Windows Speech Recognition Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2025-59515 |
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2025-60717 |
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2025-60719 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2025-62213 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2025-62215 |
Windows Kernel Elevation of Privilege Vulnerability |
7.0 |
high |
Yes |
| CVE-2025-62217 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2025-62218 |
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2025-62219 |
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability |
7.0 |
high |
|
| CVE-2025-62449 |
Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability |
6.8 |
high |
|
| CVE-2025-47179 |
Configuration Manager Elevation of Privilege Vulnerability |
6.7 |
high |
|
| CVE-2025-60708 |
Storvsp.sys Driver Denial of Service Vulnerability |
6.5 |
high |
|
| CVE-2025-60722 |
Microsoft OneDrive for Android Elevation of Privilege Vulnerability |
6.5 |
high |
|
| CVE-2025-62206 |
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
6.5 |
high |
|
| CVE-2025-60723 |
DirectX Graphics Kernel Denial of Service Vulnerability |
6.3 |
high |
|
| CVE-2025-59240 |
Microsoft Excel Information Disclosure Vulnerability |
5.5 |
high |
|
| CVE-2025-59509 |
Windows Speech Recognition Information Disclosure Vulnerability |
5.5 |
high |
|
| CVE-2025-59510 |
Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability |
5.5 |
high |
|
| CVE-2025-59513 |
Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability |
5.5 |
high |
|
| CVE-2025-60706 |
Windows Hyper-V Information Disclosure Vulnerability |
5.5 |
high |
|
| CVE-2025-62208 |
Windows License Manager Information Disclosure Vulnerability |
5.5 |
high |
|
| CVE-2025-62209 |
Windows License Manager Information Disclosure Vulnerability |
5.5 |
high |
|
| CVE-2025-62453 |
GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability |
5.0 |
high |
|
| CVE-2025-60728 |
Microsoft Excel Information Disclosure Vulnerability |
4.3 |
high |
|
| CVE-2025-31133 |
runc container escape via "masked path" abuse due to mount race conditions |
— |
high |
|
| CVE-2025-52565 |
container escape due to /dev/console mount and related races |
— |
high |
|
| CVE-2025-64324 |
KubeVirt Vulnerable to Arbitrary Host File Read and Write |
— |
high |
|
| CVE-2025-66031 |
node-forge ASN.1 Unbounded Recursion |
— |
high |
|
| CVE-2025-11230 |
Denial of service vulnerability in HAProxy mjson library |
7.5 |
medium |
|
| CVE-2025-11935 |
Forward Secrecy Violation in WolfSSL TLS 1.3 |
7.5 |
medium |
|
| CVE-2025-40158 |
ipv6: use RCU in ip6_output() |
7.1 |
medium |
|
| CVE-2025-10966 |
missing SFTP host verification with wolfSSH |
6.8 |
medium |
|
| CVE-2025-12969 |
CVE-2025-12969 |
6.5 |
medium |
|
| CVE-2025-64433 |
KubeVirt Arbitrary Container File Read |
6.5 |
medium |
|
| CVE-2025-40173 |
net/ip6_tunnel: Prevent perpetual tunnel growth |
6.2 |
medium |
|
| CVE-2025-40213 |
Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete |
6.1 |
medium |
|
| CVE-2025-64505 |
LIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index |
6.1 |
medium |
|
| CVE-2025-64506 |
LIBPNG is vulnerable to a heap buffer over-read in `png_write_image_8bit` with grayscale+alpha or RGB/RGBA images |
6.1 |
medium |
|
| CVE-2025-61915 |
OpenPrinting CUPS vulnerable to stack based out-of-bound write |
6.0 |
medium |
|
| CVE-2025-12818 |
PostgreSQL libpq undersizes allocations, via integer wraparound |
5.9 |
medium |
|
| CVE-2025-12748 |
Libvirt: denial of service in xml parsing |
5.5 |
medium |
|
| CVE-2025-13193 |
Libvirt: information disclosure via world-readable vm snapshots |
5.5 |
medium |
|
| CVE-2025-40107 |
can: hi311x: fix null pointer dereference when resuming from sleep before interface was enabled |
5.5 |
medium |
|
| CVE-2025-40136 |
crypto: hisilicon/qm - request reserved interrupt for virtual function |
5.5 |
medium |
|
| CVE-2025-40146 |
blk-mq: fix potential deadlock while nr_requests grown |
5.5 |
medium |
|
| CVE-2025-40149 |
tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock(). |
5.5 |
medium |
|
| CVE-2025-40164 |
usbnet: Fix using smp_processor_id() in preemptible code warnings |
5.5 |
medium |
|
| CVE-2025-40167 |
ext4: detect invalid INLINE_DATA + EXTENTS flag combination |
5.5 |
medium |
|
| CVE-2025-40168 |
smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). |
5.5 |
medium |
|
| CVE-2025-40178 |
pid: Add a judgment for ns null in pid_nr_ns |
5.5 |
medium |
|
| CVE-2025-40179 |
ext4: verify orphan file size is not too big |
5.5 |
medium |
|
| CVE-2025-40180 |
mailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop |
5.5 |
medium |
|
| CVE-2025-40187 |
net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() |
5.5 |
medium |
|
| CVE-2025-40188 |
pwm: berlin: Fix wrong register in suspend/resume |
5.5 |
medium |
|
| CVE-2025-40192 |
Revert "ipmi: fix msg stack when IPMI is disconnected" |
5.5 |
medium |
|
| CVE-2025-40193 |
xtensa: simdisk: add input size check in proc_write_simdisk |
5.5 |
medium |
|
| CVE-2025-40194 |
cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request() |
5.5 |
medium |
|
| CVE-2025-40195 |
mount: handle NULL values in mnt_ns_release() |
5.5 |
medium |
|
| CVE-2025-40197 |
media: mc: Clear minor number before put device |
5.5 |
medium |
|
| CVE-2025-40200 |
Squashfs: reject negative file sizes in squashfs_read_inode() |
5.5 |
medium |
|
| CVE-2025-40202 |
ipmi: Rework user message limit handling |
5.5 |
medium |
|
| CVE-2025-40206 |
netfilter: nft_objref: validate objref and objrefmap expressions |
5.5 |
medium |
|
| CVE-2025-40207 |
media: v4l2-subdev: Fix alloc failure check in v4l2_subdev_call_state_try() |
5.5 |
medium |
|
| CVE-2025-40210 |
Revert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND" |
5.5 |
medium |
|
| CVE-2025-60753 |
An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash). |
5.5 |
medium |
|
| CVE-2025-10158 |
Rsync: Out of bounds array access via negative index |
5.4 |
medium |
|
| CVE-2025-11936 |
Potential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHello |
5.3 |
medium |
|
| CVE-2025-12875 |
mruby array.c ary_fill_exec out-of-bounds write |
5.3 |
medium |
|
| CVE-2025-13120 |
mruby array.c sort_cmp use after free |
5.3 |
medium |
|
| CVE-2025-64435 |
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation |
5.3 |
medium |
|
| CVE-2025-64436 |
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes |
5.3 |
medium |
|
| CVE-2025-58436 |
OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack |
5.1 |
medium |
|
| CVE-2025-64713 |
WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode |
5.1 |
medium |
|