Vulnerability index

Browse CVEs

7,933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 7.8 CVE-2025-49700 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-07-08 HIGH 8.4 CVE-2025-49695 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-07-08 HIGH 7.3 CVE-2025-49682 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.6093 / 10.0.19045.6093+ Fix from $1,9502025-07-08 HIGH 7.0 CVE-2025-49685 Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7558 / 10.0.19044.6093+ Fix from $1,9502025-07-08 HIGH 7.0 CVE-2025-49677 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.5624+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49675 Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49665 Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elev… Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49660 Use after free in Windows Event Tracing allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.1 CVE-2025-48821 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-48806 Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-48000 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47991 Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-47986 Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47976 Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-27050 Memory corruption while processing event close when client process terminates abruptly. Aqt1000 Firmware No fix yet Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-27056 Memory corruption during sub-system restart while processing clean-up to free up resources. Fastconnect 7800 Firmware Patch available Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-21466 Memory corruption while processing a private escape command in an event trigger. Aqt1000 Firmware No fix yet Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-27047 Memory corruption while processing the TESTPATTERNCONFIG escape path. Fastconnect 6700 Firmware No fix yet Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-38236 In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't leave consecutive consumed OOB skbs. Jann Horn reported a use-af… Linux Kernel 5.15.194 / 6.1.143+ Fix from $1,9502025-07-08 MEDIUM 5.5 CVE-2025-53185 Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory Impact: Success… Emui Mitigation only Fix from $1,6002025-07-07 HIGH 7.8 CVE-2025-38227 In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the subsequent process of initialization failure syzb… Linux Kernel 5.10.239 / 5.15.186+ Fix from $1,9502025-07-04 HIGH 7.8 CVE-2025-38209 In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: remove tag set when second admin queue config fails Commit 104d0e2f62… Linux Kernel 6.15.4+ Fix from $1,9502025-07-04 HIGH 7.8 CVE-2025-38211 In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction The commi… Linux Kernel 5.4.296 / 5.10.240+ Fix from $1,9502025-07-04 HIGH 7.8 CVE-2025-38212 In the Linux kernel, the following vulnerability has been resolved: ipc: fix to protect IPCS lookups using RCU syzbot reported that it discovered a… Linux Kernel 5.4.295 / 5.10.239+ Fix from $1,9502025-07-04 HIGH 7.8 CVE-2025-38187 In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() The RPC container is r… Linux Kernel 6.15.4+ Fix from $1,9502025-07-04 HIGH 7.8 CVE-2025-38180 In the Linux kernel, the following vulnerability has been resolved: net: atm: fix /proc/net/atm/lec handling /proc/net/atm/lec must ensure safety a… Linux Kernel 5.4.295 / 5.10.239+ Fix from $1,9502025-07-04 HIGH 7.8 CVE-2025-38175 In the Linux kernel, the following vulnerability has been resolved: binder: fix yet another UAF in binder_devices Commit e77aff5528a18 ("binderfs: … Linux Kernel 6.14.11 / 6.15.2+ Fix from $1,9502025-07-04 HIGH 7.8 CVE-2025-38176 In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in binderfs_evict_inode() Running 'stress-ng --binde… Linux Kernel 6.14.11 / 6.15.2+ Fix from $1,9502025-07-04 HIGH 7.8 CVE-2025-38172 In the Linux kernel, the following vulnerability has been resolved: erofs: avoid using multiple devices with different type For multiple devices, b… Linux Kernel 6.12.34 / 6.15.3+ Fix from $1,9502025-07-03 HIGH 7.8 CVE-2025-38154 In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Avoid using sk_socket after free when sending The sk->sk_socket i… Linux Kernel 5.15.186 / 6.1.142+ Fix from $1,9502025-07-03