| CVE-2025-62168 |
Squid vulnerable to information disclosure via authentication credential leakage in error handling |
10.0 |
critical |
|
| CVE-2025-59503 |
Azure Compute Resource Provider Elevation of Privilege Vulnerability |
10.0 |
critical |
|
| CVE-2025-49844 |
Redis Lua Use-After-Free may lead to remote code execution |
9.9 |
critical |
|
| CVE-2025-49708 |
Microsoft Graphics Component Elevation of Privilege Vulnerability |
9.9 |
critical |
|
| CVE-2025-39898 |
e1000e: fix heap overflow in e1000_set_eeprom |
9.8 |
critical |
|
| CVE-2025-39907 |
mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer |
9.8 |
critical |
|
| CVE-2025-39910 |
mm/vmalloc, mm/kasan: respect gfp mask in kasan_populate_vmalloc() |
9.8 |
critical |
|
| CVE-2025-39925 |
can: j1939: implement NETDEV_UNREGISTER notification handler |
9.8 |
critical |
|
| CVE-2025-39943 |
ksmbd: smbdirect: validate data_offset and data_length field of smb_direct_data_transfer |
9.8 |
critical |
|
| CVE-2025-39967 |
fbcon: fix integer overflow in fbcon_do_set_font |
9.8 |
critical |
|
| CVE-2025-39968 |
i40e: add max boundary check for VF filters |
9.8 |
critical |
|
| CVE-2025-39970 |
i40e: fix input validation logic for action_meta |
9.8 |
critical |
|
| CVE-2025-39971 |
i40e: fix idx validation in config queues msg |
9.8 |
critical |
|
| CVE-2025-39972 |
i40e: fix idx validation in i40e_validate_queue_map |
9.8 |
critical |
|
| CVE-2025-39973 |
i40e: add validation for ring_len param |
9.8 |
critical |
|
| CVE-2025-39978 |
octeontx2-pf: Fix potential use after free in otx2_tc_add_flow() |
9.8 |
critical |
|
| CVE-2025-39985 |
can: mcba_usb: populate ndo_change_mtu() to prevent buffer overflow |
9.8 |
critical |
|
| CVE-2025-39986 |
can: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow |
9.8 |
critical |
|
| CVE-2025-39994 |
media: tuner: xc5000: Fix use-after-free in xc5000_release |
9.8 |
critical |
|
| CVE-2025-39996 |
media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove |
9.8 |
critical |
|
| CVE-2025-40000 |
wifi: rtw89: fix use-after-free in rtw89_core_tx_kick_off_and_wait() |
9.8 |
critical |
|
| CVE-2025-59246 |
Azure Entra ID Elevation of Privilege Vulnerability |
9.8 |
critical |
|
| CVE-2025-59287 |
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
9.8 |
critical |
Yes |
| CVE-2025-59218 |
Azure Entra ID Elevation of Privilege Vulnerability |
9.6 |
critical |
|
| CVE-2025-55321 |
Azure Monitor Log Analytics Spoofing Vulnerability |
9.3 |
critical |
|
| CVE-2025-59252 |
M365 Copilot Information Disclosure Vulnerability |
9.3 |
critical |
|
| CVE-2025-59272 |
Copilot Information Disclosure Vulnerability |
9.3 |
critical |
|
| CVE-2025-59286 |
Copilot Information Disclosure Vulnerability |
9.3 |
critical |
|
| CVE-2025-59247 |
Azure PlayFab Elevation of Privilege Vulnerability |
8.8 |
critical |
|
| CVE-2025-59271 |
Redis Enterprise Elevation of Privilege Vulnerability |
8.7 |
critical |
|
| CVE-2025-59236 |
Microsoft Excel Remote Code Execution Vulnerability |
8.4 |
critical |
|
| CVE-2025-0033 |
AMD CVE-2025-0033: RMP Corruption During SNP Initialization |
8.2 |
critical |
|
| CVE-2025-59291 |
Confidential Azure Container Instances Elevation of Privilege Vulnerability |
8.2 |
critical |
|
| CVE-2025-59292 |
Azure Compute Gallery Elevation of Privilege Vulnerability |
8.2 |
critical |
|
| CVE-2025-59227 |
Microsoft Office Remote Code Execution Vulnerability |
7.8 |
critical |
|
| CVE-2025-59234 |
Microsoft Office Remote Code Execution Vulnerability |
7.8 |
critical |
|
| CVE-2025-59500 |
Azure Notification Service Elevation of Privilege Vulnerability |
7.7 |
critical |
|
| CVE-2025-59273 |
Azure Event Grid System Elevation of Privilege Vulnerability |
7.3 |
critical |
|
| CVE-2016-9535 |
MITRE CVE-2016-9535: LibTIFF Heap Buffer Overflow Vulnerability |
4.0 |
critical |
|
| CVE-2025-55315 |
ASP.NET Security Feature Bypass Vulnerability |
9.9 |
high |
|
| CVE-2025-10729 |
Use-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVG |
9.3 |
high |
|
| CVE-2025-58715 |
Windows Speech Runtime Elevation of Privilege Vulnerability |
8.8 |
high |
|
| CVE-2025-58716 |
Windows Speech Runtime Elevation of Privilege Vulnerability |
8.8 |
high |
|
| CVE-2025-58718 |
Remote Desktop Client Remote Code Execution Vulnerability |
8.8 |
high |
|
| CVE-2025-59213 |
Configuration Manager Elevation of Privilege Vulnerability |
8.8 |
high |
|
| CVE-2025-59228 |
Microsoft SharePoint Remote Code Execution Vulnerability |
8.8 |
high |
|
| CVE-2025-59237 |
Microsoft SharePoint Remote Code Execution Vulnerability |
8.8 |
high |
|
| CVE-2025-59249 |
Microsoft Exchange Server Elevation of Privilege Vulnerability |
8.8 |
high |
|
| CVE-2025-59295 |
Windows URL Parsing Remote Code Execution Vulnerability |
8.8 |
high |
|
| CVE-2025-40778 |
Cache poisoning attacks with unsolicited RRs |
8.6 |
high |
|
| CVE-2025-40780 |
Cache poisoning due to weak PRNG |
8.6 |
high |
|
| CVE-2025-40048 |
uio_hv_generic: Let userspace take care of interrupt mask |
8.4 |
high |
|
| CVE-2025-53782 |
Microsoft Exchange Server Elevation of Privilege Vulnerability |
8.4 |
high |
|
| CVE-2025-59489 |
MITRE: CVE-2025-59489 Unity Gaming Engine Editor vulnerability |
8.4 |
high |
|
| CVE-2025-62518 |
astral-tokio-tar Vulnerable to PAX Header Desynchronization |
8.1 |
high |
|
| CVE-2025-59250 |
JDBC Driver for SQL Server Spoofing Vulnerability |
8.1 |
high |
|
| CVE-2023-53543 |
vdpa: Add max vqp attr to vdpa_nl_policy for nlattr length check |
7.8 |
high |
|
| CVE-2025-39944 |
octeontx2-pf: Fix use-after-free bugs in otx2_sync_tstamp() |
7.8 |
high |
|
| CVE-2025-39945 |
cnic: Fix use-after-free bugs in cnic_delete_task |
7.8 |
high |
|
| CVE-2025-39952 |
wifi: wilc1000: avoid buffer overflow in WID string configuration |
7.8 |
high |
|
| CVE-2025-39977 |
futex: Prevent use-after-free during requeue-PI |
7.8 |
high |
|
| CVE-2025-39982 |
Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync |
7.8 |
high |
|
| CVE-2025-39998 |
scsi: target: target_core_configfs: Add length check to avoid buffer overflow |
7.8 |
high |
|
| CVE-2025-40001 |
scsi: mvsas: Fix use-after-free bugs in mvs_work_queue |
7.8 |
high |
|
| CVE-2025-40003 |
net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work |
7.8 |
high |
|
| CVE-2025-40055 |
ocfs2: fix double free in user_cluster_connect() |
7.8 |
high |
|
| CVE-2025-40068 |
fs: ntfs3: Fix integer overflow in run_unpack() |
7.8 |
high |
|
| CVE-2025-40077 |
f2fs: fix to avoid overflow while left shift operation |
7.8 |
high |
|
| CVE-2025-40096 |
drm/sched: Fix potential double free in drm_sched_job_add_resv_dependencies |
7.8 |
high |
|
| CVE-2025-62229 |
Xorg: xmayland: use-after-free in xpresentnotify structure creation |
7.8 |
high |
|
| CVE-2025-24052 |
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-24990 |
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
7.8 |
high |
Yes |
| CVE-2025-50152 |
Windows Kernel Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-50175 |
Windows Digital Media Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-53150 |
Windows Digital Media Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-53768 |
Xbox IStorageService Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-55328 |
Windows Hyper-V Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-55339 |
Windows Network Driver Interface Specification (NDIS) Driver Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-55677 |
Windows Device Association Broker Service Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-55680 |
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-55692 |
Windows Error Reporting Service Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-55694 |
Windows Error Reporting Service Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-55696 |
NtQueryInformation Token function (ntifs.h) Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-55697 |
Azure Local Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-55701 |
Windows Authentication Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-58714 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-58720 |
Windows Cryptographic Services Information Disclosure Vulnerability |
7.8 |
high |
|
| CVE-2025-58722 |
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-58724 |
Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-58728 |
Windows Bluetooth Service Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59187 |
Windows Kernel Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59191 |
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59192 |
Storport.sys Driver Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59199 |
Software Protection Platform (SPP) Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59201 |
Network Connection Status Indicator (NCSI) Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59207 |
Windows Kernel Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59222 |
Microsoft Word Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-59223 |
Microsoft Excel Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-59224 |
Microsoft Excel Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-59225 |
Microsoft Excel Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-59226 |
Microsoft Office Visio Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-59230 |
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
7.8 |
high |
Yes |
| CVE-2025-59231 |
Microsoft Excel Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-59233 |
Microsoft Excel Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-59238 |
Microsoft PowerPoint Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-59241 |
Windows Health and Optimized Experiences Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59242 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59243 |
Microsoft Excel Remote Code Execution Vulnerability |
7.8 |
high |
|
| CVE-2025-59254 |
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59255 |
Windows DWM Core Library Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59275 |
Windows Authentication Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59277 |
Windows Authentication Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59278 |
Windows Authentication Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59281 |
Xbox Gaming Services Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59290 |
Windows Bluetooth Service Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-59494 |
Azure Monitor Agent Elevation of Privilege Vulnerability |
7.8 |
high |
|
| CVE-2025-47912 |
Insufficient validation of bracketed IPv6 hostnames in net/url |
7.7 |
high |
|
| CVE-2025-53139 |
Windows Hello Security Feature Bypass Vulnerability |
7.7 |
high |
|
| CVE-2025-55698 |
DirectX Graphics Kernel Denial of Service Vulnerability |
7.7 |
high |
|
| CVE-2025-59200 |
Data Sharing Service Spoofing Vulnerability |
7.7 |
high |
|
| CVE-2025-12105 |
Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completion |
7.5 |
high |
|
| CVE-2025-58187 |
Quadratic complexity when checking name constraints in crypto/x509 |
7.5 |
high |
|
| CVE-2025-59530 |
quic-go has Client Crash Due to Premature HANDSHAKE_DONE Frame |
7.5 |
high |
|
| CVE-2025-61099 |
FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet. |
7.5 |
high |
|
| CVE-2025-61100 |
FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions. |
7.5 |
high |
|
| CVE-2025-61101 |
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. |
7.5 |
high |
|
| CVE-2025-61104 |
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. |
7.5 |
high |
|
| CVE-2025-61723 |
Quadratic complexity when parsing some invalid inputs in encoding/pem |
7.5 |
high |
|
| CVE-2025-8677 |
Resource exhaustion via malformed DNSKEY handling |
7.5 |
high |
|
| CVE-2025-55326 |
Windows Connected Devices Platform Service (Cdpsvc) Remote Code Execution Vulnerability |
7.5 |
high |
|
| CVE-2025-58726 |
Windows SMB Server Elevation of Privilege Vulnerability |
7.5 |
high |
|
| CVE-2025-59248 |
Microsoft Exchange Server Spoofing Vulnerability |
7.5 |
high |
|
| CVE-2025-48004 |
Microsoft Brokering File System Elevation of Privilege Vulnerability |
7.4 |
high |
|
| CVE-2025-55335 |
Windows NTFS Elevation of Privilege Vulnerability |
7.4 |
high |
|
| CVE-2025-55687 |
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability |
7.4 |
high |
|
| CVE-2025-55693 |
Windows Kernel Elevation of Privilege Vulnerability |
7.4 |
high |
|
| CVE-2025-59189 |
Microsoft Brokering File System Elevation of Privilege Vulnerability |
7.4 |
high |
|
| CVE-2025-59206 |
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability |
7.4 |
high |
|
| CVE-2025-59210 |
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability |
7.4 |
high |
|
| CVE-2025-39987 |
can: hi311x: populate ndo_change_mtu() to prevent buffer overflow |
7.3 |
high |
|
| CVE-2025-39988 |
can: etas_es58x: populate ndo_change_mtu() to prevent buffer overflow |
7.3 |
high |
|
| CVE-2025-62230 |
Xorg: xwayland: use-after-free in xkb client resource removal |
7.3 |
high |
|
| CVE-2025-25004 |
PowerShell Elevation of Privilege Vulnerability |
7.3 |
high |
|
| CVE-2025-55240 |
Visual Studio Elevation of Privilege Vulnerability |
7.3 |
high |
|
| CVE-2025-55247 |
.NET Elevation of Privilege Vulnerability |
7.3 |
high |
|
| CVE-2023-53469 |
af_unix: Fix null-ptr-deref in unix_stream_sendpage(). |
7.1 |
high |
|
| CVE-2025-39901 |
i40e: remove read access to debugfs files |
7.1 |
high |
|
| CVE-2025-39980 |
nexthop: Forbid FDB status change while nexthop is in a group |
7.1 |
high |
|
| CVE-2025-39993 |
media: rc: fix races with imon_disconnect() |
7.1 |
high |
|
| CVE-2025-39995 |
media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe |
7.1 |
high |
|