Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
365 Apps HIGH 7.8
CVE-2025-49700

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-07-08
365 Apps HIGH 8.4
CVE-2025-49695

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-07-08
Windows 10 21h2 HIGH 7.3
CVE-2025-49682

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.6093 / 10.0.19045.6093+
Fix from $1,950 2025-07-08
Windows 10 1809 HIGH 7.0
CVE-2025-49685

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7558 / 10.0.19044.6093+
Fix from $1,950 2025-07-08
Windows 11 22h2 HIGH 7.0
CVE-2025-49677

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22621.5624+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-49675

Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-49665

Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elev…

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-49660

Use after free in Windows Event Tracing allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.1
CVE-2025-48821

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-48806

Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1607 HIGH 7.8
CVE-2025-48000

Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Windows 10 1607 HIGH 7.8
CVE-2025-47991

Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 8.8
CVE-2025-47986

Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-47976

Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Aqt1000 Firmware HIGH 7.8
CVE-2025-27050

Memory corruption while processing event close when client process terminates abruptly.

No fix yet
Fix from $1,950 2025-07-08
Fastconnect 7800 Firmware HIGH 7.8
CVE-2025-27056

Memory corruption during sub-system restart while processing clean-up to free up resources.

Patch available
Fix from $1,950 2025-07-08
Aqt1000 Firmware HIGH 7.8
CVE-2025-21466

Memory corruption while processing a private escape command in an event trigger.

No fix yet
Fix from $1,950 2025-07-08
Fastconnect 6700 Firmware HIGH 7.8
CVE-2025-27047

Memory corruption while processing the TESTPATTERNCONFIG escape path.

No fix yet
Fix from $1,950 2025-07-08
Linux Kernel HIGH 7.8
CVE-2025-38236

In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't leave consecutive consumed OOB skbs. Jann Horn reported a use-af…

Fix: 5.15.194 / 6.1.143+
Fix from $1,950 2025-07-08
Emui MEDIUM 5.5
CVE-2025-53185

Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory Impact: Success…

Mitigation only
Fix from $1,600 2025-07-07
Linux Kernel HIGH 7.8
CVE-2025-38227

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the subsequent process of initialization failure syzb…

Fix: 5.10.239 / 5.15.186+
Fix from $1,950 2025-07-04
Linux Kernel HIGH 7.8
CVE-2025-38209

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: remove tag set when second admin queue config fails Commit 104d0e2f62…

Fix: 6.15.4+
Fix from $1,950 2025-07-04
Linux Kernel HIGH 7.8
CVE-2025-38211

In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction The commi…

Fix: 5.4.296 / 5.10.240+
Fix from $1,950 2025-07-04
Linux Kernel HIGH 7.8
CVE-2025-38212

In the Linux kernel, the following vulnerability has been resolved: ipc: fix to protect IPCS lookups using RCU syzbot reported that it discovered a…

Fix: 5.4.295 / 5.10.239+
Fix from $1,950 2025-07-04
Linux Kernel HIGH 7.8
CVE-2025-38187

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() The RPC container is r…

Fix: 6.15.4+
Fix from $1,950 2025-07-04
Linux Kernel HIGH 7.8
CVE-2025-38180

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix /proc/net/atm/lec handling /proc/net/atm/lec must ensure safety a…

Fix: 5.4.295 / 5.10.239+
Fix from $1,950 2025-07-04
Linux Kernel HIGH 7.8
CVE-2025-38175

In the Linux kernel, the following vulnerability has been resolved: binder: fix yet another UAF in binder_devices Commit e77aff5528a18 ("binderfs: …

Fix: 6.14.11 / 6.15.2+
Fix from $1,950 2025-07-04
Linux Kernel HIGH 7.8
CVE-2025-38176

In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in binderfs_evict_inode() Running 'stress-ng --binde…

Fix: 6.14.11 / 6.15.2+
Fix from $1,950 2025-07-04
Linux Kernel HIGH 7.8
CVE-2025-38172

In the Linux kernel, the following vulnerability has been resolved: erofs: avoid using multiple devices with different type For multiple devices, b…

Fix: 6.12.34 / 6.15.3+
Fix from $1,950 2025-07-03
Linux Kernel HIGH 7.8
CVE-2025-38154

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Avoid using sk_socket after free when sending The sk->sk_socket i…

Fix: 5.15.186 / 6.1.142+
Fix from $1,950 2025-07-03