Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2025-53809
Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
Windows 11 24h2
10.0.26100.6508+
HIGH 7.5
CVE-2025-53805
Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.
Windows 11 22h2
10.0.20348.4106 / 10.0.22621.5909+
HIGH 7.0
CVE-2025-53807
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized atta…
Windows 10 1809
10.0.17763.7792 / 10.0.19044.6332+
MEDIUM 6.7
CVE-2025-53808
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege…
Windows 10 1507
10.0.10240.21128 / 10.0.14393.8422+
MEDIUM 6.5
CVE-2025-53806
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
Windows Server 2008
10.0.14393.8422 / 10.0.17763.7792+
MEDIUM 5.5
CVE-2025-53804
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21128 / 10.0.14393.8422+
HIGH 7.8
CVE-2025-53800
No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8422 / 10.0.17763.7792+
HIGH 7.8
CVE-2025-53801
Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21128 / 10.0.14393.8422+
HIGH 7.0
CVE-2025-53802
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Windows 10 21h2
10.0.19044.6332 / 10.0.19045.6332+
MEDIUM 5.5
CVE-2025-53799
Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
365 Copilot
10.0.10240.21128 / 10.0.14393.8422+
MEDIUM 5.5
CVE-2025-53803
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21128 / 10.0.14393.8422+
MEDIUM 6.5
CVE-2025-53796
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
Windows Server 2008
10.0.14393.8422 / 10.0.17763.7792+
MEDIUM 6.5
CVE-2025-53797
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
Windows Server 2008
10.0.14393.8422 / 10.0.17763.7792+
MEDIUM 6.5
CVE-2025-53798
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
Windows Server 2008
10.0.14393.8422 / 10.0.17763.7792+
HIGH 7.0
CVE-2025-49734
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.
Powershell
7.4.12 / 7.5.3+
HIGH 7.8
CVE-2025-49692
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
Azure Connected Machine Agent
1.49+
MEDIUM 5.3
CVE-2025-47997
Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose i…
Sql Server 2016
13.0.6470.1 / 13.0.7065.1+
CRITICAL 9.0
CVE-2025-55244
Azure Bot Service Elevation of Privilege Vulnerability
Azure Ai Bot Service
No fix yet
HIGH 7.5
CVE-2025-55242
Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network.
Xbox Gaming Services
No fix yet
CRITICAL 10.0
CVE-2025-55241
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
CRITICAL 9.8
CVE-2025-54914
Azure Networking Elevation of Privilege Vulnerability
Azure Networking
No fix yet
HIGH 7.5
CVE-2025-55238
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
Dynamics 365
No fix yet
HIGH 7.8
CVE-2025-9491EPSS 69%
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary …
Windows 11 23h2
Mitigation only
HIGH 7.8
CVE-2025-55230
Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.5
CVE-2025-55231
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to exe…
Windows Server 2012
10.0.14393.8416 / 10.0.17763.7783+
MEDIUM 5.3
CVE-2025-55229
Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
CRITICAL 9.8
CVE-2025-53795
Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.
Pc Manager
Mitigation only
CRITICAL 9.8
CVE-2025-53763
Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
Purview Data Governance
No fix yet
HIGH 7.8
CVE-2025-53789
Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.5
CVE-2025-53793
Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.
Azure Stack Hub
1.2406.1.23 / 1.2408.1.50+