Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2025-49700
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2025-49695
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.3
CVE-2025-49682
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
Windows 10 21h2
10.0.19044.6093 / 10.0.19045.6093+
HIGH 7.0
CVE-2025-49685
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7558 / 10.0.19044.6093+
HIGH 7.0
CVE-2025-49677
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Windows 11 22h2
10.0.22621.5624+
HIGH 7.8
CVE-2025-49675
Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.8
CVE-2025-49665
Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elev…
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.8
CVE-2025-49660
Use after free in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.1
CVE-2025-48821
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.8
CVE-2025-48806
Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.8
CVE-2025-48000
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8246 / 10.0.17763.7558+
HIGH 7.8
CVE-2025-47991
Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8246 / 10.0.17763.7558+
HIGH 8.8
CVE-2025-47986
Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.8
CVE-2025-47976
Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.8
CVE-2025-27050
Memory corruption while processing event close when client process terminates abruptly.
Aqt1000 Firmware
No fix yet
HIGH 7.8
CVE-2025-27056
Memory corruption during sub-system restart while processing clean-up to free up resources.
Fastconnect 7800 Firmware
Patch available
HIGH 7.8
CVE-2025-21466
Memory corruption while processing a private escape command in an event trigger.
Aqt1000 Firmware
No fix yet
HIGH 7.8
CVE-2025-27047
Memory corruption while processing the TESTPATTERNCONFIG escape path.
Fastconnect 6700 Firmware
No fix yet
HIGH 7.8
CVE-2025-38236
In the Linux kernel, the following vulnerability has been resolved:
af_unix: Don't leave consecutive consumed OOB skbs.
Jann Horn reported a use-af…
Linux Kernel
5.15.194 / 6.1.143+
MEDIUM 5.5
CVE-2025-53185
Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory
Impact: Success…
Emui
Mitigation only
HIGH 7.8
CVE-2025-38227
In the Linux kernel, the following vulnerability has been resolved:
media: vidtv: Terminating the subsequent process of initialization failure
syzb…
Linux Kernel
5.10.239 / 5.15.186+
HIGH 7.8
CVE-2025-38209
In the Linux kernel, the following vulnerability has been resolved:
nvme-tcp: remove tag set when second admin queue config fails
Commit 104d0e2f62…
Linux Kernel
6.15.4+
HIGH 7.8
CVE-2025-38211
In the Linux kernel, the following vulnerability has been resolved:
RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction
The commi…
Linux Kernel
5.4.296 / 5.10.240+
HIGH 7.8
CVE-2025-38212
In the Linux kernel, the following vulnerability has been resolved:
ipc: fix to protect IPCS lookups using RCU
syzbot reported that it discovered a…
Linux Kernel
5.4.295 / 5.10.239+
HIGH 7.8
CVE-2025-38187
In the Linux kernel, the following vulnerability has been resolved:
drm/nouveau: fix a use-after-free in r535_gsp_rpc_push()
The RPC container is r…
Linux Kernel
6.15.4+
HIGH 7.8
CVE-2025-38180
In the Linux kernel, the following vulnerability has been resolved:
net: atm: fix /proc/net/atm/lec handling
/proc/net/atm/lec must ensure safety a…
Linux Kernel
5.4.295 / 5.10.239+
HIGH 7.8
CVE-2025-38175
In the Linux kernel, the following vulnerability has been resolved:
binder: fix yet another UAF in binder_devices
Commit e77aff5528a18 ("binderfs: …
Linux Kernel
6.14.11 / 6.15.2+
HIGH 7.8
CVE-2025-38176
In the Linux kernel, the following vulnerability has been resolved:
binder: fix use-after-free in binderfs_evict_inode()
Running 'stress-ng --binde…
Linux Kernel
6.14.11 / 6.15.2+
HIGH 7.8
CVE-2025-38172
In the Linux kernel, the following vulnerability has been resolved:
erofs: avoid using multiple devices with different type
For multiple devices, b…
Linux Kernel
6.12.34 / 6.15.3+
HIGH 7.8
CVE-2025-38154
In the Linux kernel, the following vulnerability has been resolved:
bpf, sockmap: Avoid using sk_socket after free when sending
The sk->sk_socket i…
Linux Kernel
5.15.186 / 6.1.142+