Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2025-32709 KEV
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 7.8
CVE-2025-30393
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-30400 KEV
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7314 / 10.0.19044.5854+
HIGH 7.8
CVE-2025-32701 KEV
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 7.8
CVE-2025-30385
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8066 / 10.0.17763.7314+
HIGH 7.8
CVE-2025-30386
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.18827.20000+
HIGH 7.8
CVE-2025-30377
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20010+
HIGH 7.8
CVE-2025-29977
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20010+
HIGH 7.8
CVE-2025-29978
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-29970
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.25398.1611 / 10.0.26100.4061+
HIGH 7.0
CVE-2025-29841
Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorize…
Windows 10 21h2
10.0.19044.5854 / 10.0.19045.5854+
HIGH 7.5
CVE-2025-29831
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
Windows Server 2008
10.0.14393.8066 / 10.0.17763.7314+
HIGH 7.8
CVE-2023-53145
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition…
Linux Kernel
4.14.326 / 4.19.295+
HIGH 7.8
CVE-2025-37882
In the Linux kernel, the following vulnerability has been resolved:
usb: xhci: Fix isochronous Ring Underrun/Overrun event handling
The TRB pointer…
Linux Kernel
6.12.26 / 6.14.5+
HIGH 7.8
CVE-2025-37885
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Reset IRTE to host control if *new* route isn't postable
Restore an I…
Linux Kernel
5.10.237 / 5.15.181+
HIGH 7.8
CVE-2025-37861
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue
When t…
Linux Kernel
6.12.24 / 6.13.12+
HIGH 7.8
CVE-2025-37869
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Use local fence in error path of xe_migrate_clear
The intent of the err…
Linux Kernel
6.12.25 / 6.14.4+
HIGH 7.8
CVE-2025-37854
In the Linux kernel, the following vulnerability has been resolved:
drm/amdkfd: Fix mode1 reset crash issue
If HW scheduler hangs and mode1 reset i…
Linux Kernel
6.1.135 / 6.6.88+
HIGH 7.8
CVE-2025-37845
In the Linux kernel, the following vulnerability has been resolved:
tracing: fprobe events: Fix possible UAF on modules
Commit ac91052f0ae5 ("traci…
Linux Kernel
6.12.24 / 6.13.12+
HIGH 7.8
CVE-2025-37849
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Tear down vGIC on failed vCPU creation
If kvm_arch_vcpu_create() fa…
Linux Kernel
6.1.135 / 6.6.88+
MEDIUM 6.2
CVE-2025-31946
Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a crafted DICOM file and cause me…
Mitigation only
HIGH 7.5
CVE-2025-27578
Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption…
Mitigation only
HIGH 7.8
CVE-2025-37819
In the Linux kernel, the following vulnerability has been resolved:
irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode()
With ACPI in pla…
Linux Kernel
5.4.294 / 5.10.238+
HIGH 7.8
CVE-2025-37823
In the Linux kernel, the following vulnerability has been resolved:
net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too
Similarly to the pre…
Linux Kernel
5.4.293 / 5.10.237+
HIGH 8.8
CVE-2025-4372
Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…
Chrome
136.0.7103.92+
HIGH 7.8
CVE-2025-21453
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
315 5g Iot Modem Firmware
Patch available
HIGH 7.8
CVE-2024-45583
Memory corruption while handling multiple IOCTL calls from userspace to operate DMA operations.
Fastconnect 7800 Firmware
Patch available
HIGH 7.8
CVE-2024-45567
Memory corruption while encoding JPEG format.
Fastconnect 6900 Firmware
Patch available
HIGH 7.8
CVE-2024-45562
Memory corruption during concurrent access to server info object due to unprotected critical field.
C V2x 9150 Firmware
Patch available
HIGH 7.8
CVE-2024-45564
Memory corruption during concurrent access to server info object due to incorrect reference count update.
C V2x 9150 Firmware
Patch available