Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2025-62203
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20068+
HIGH 7.1
CVE-2025-62202
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
365 Apps
16.0.10417.20068+
CRITICAL 9.8
CVE-2025-60724EPSS 6%
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
365 Copilot
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.8
CVE-2025-60727
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20068+
HIGH 7.1
CVE-2025-60726
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
365 Apps
16.0.10417.20068+
HIGH 7.8
CVE-2025-60718
Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.7092 / 10.0.26200.7092+
HIGH 7.8
CVE-2025-60720
Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.8
CVE-2025-60721
Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.7092 / 10.0.26200.7092+
HIGH 7.0
CVE-2025-60719
Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
MEDIUM 6.5
CVE-2025-60722
Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privi…
Onedrive
7.42+
MEDIUM 6.3
CVE-2025-60723
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny …
Windows 10 1809
10.0.17763.8027 / 10.0.19044.6575+
HIGH 8.0
CVE-2025-60715
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.8
CVE-2025-60710 KEV
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges …
Windows 11 24h2
10.0.26100.7392 / 10.0.26200.7392+
HIGH 7.8
CVE-2025-60713
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
Windows Server 2016
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.8
CVE-2025-60714
Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.0
CVE-2025-60716
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8027 / 10.0.19044.6575+
HIGH 7.0
CVE-2025-60717
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8027 / 10.0.19044.6575+
HIGH 7.8
CVE-2025-60705
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.8
CVE-2025-60707
Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8027 / 10.0.19044.6575+
HIGH 7.8
CVE-2025-60709
Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.5
CVE-2025-60704
Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
MEDIUM 6.5
CVE-2025-60708
Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
MEDIUM 5.5
CVE-2025-60706
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.8
CVE-2025-59511
External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8027 / 10.0.19044.6575+
HIGH 7.8
CVE-2025-59512
Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.8
CVE-2025-59514
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.8
CVE-2025-60703
Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.0
CVE-2025-59515
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8027 / 10.0.19044.6575+
MEDIUM 5.5
CVE-2025-59513
Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.8
CVE-2025-59505
Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+