Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-49739
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
Visual Studio
15.9.75 / 16.11.49+
HIGH 8.1
CVE-2025-49735
Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
Windows Server 2012
10.0.14393.8148 / 10.0.17763.7434+
HIGH 7.8
CVE-2025-49733
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7558 / 10.0.19044.6093+
HIGH 7.8
CVE-2025-49738
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Pc Manager
3.17.4.0+
HIGH 7.0
CVE-2025-49737
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to eleva…
Teams
25163.3001.3726.6503+
HIGH 8.8
CVE-2025-49729
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+
HIGH 7.8
CVE-2025-49730
Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.8
CVE-2025-49732
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 8.8
CVE-2025-49723
Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.
Windows 10 1809
10.0.17763.7558 / 10.0.19044.6093+
HIGH 8.8
CVE-2025-49724EPSS 8%
Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network.
Windows 10 1809
10.0.17763.7558 / 10.0.19044.6093+
HIGH 7.8
CVE-2025-49725
Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8246 / 10.0.17763.7558+
HIGH 7.8
CVE-2025-49726
Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8246 / 10.0.17763.7558+
HIGH 7.0
CVE-2025-49727
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 8.5
CVE-2025-49717
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Sql Server 2019
15.0.2135.5 / 15.0.4435.7+
HIGH 7.8
CVE-2025-49721
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.5
CVE-2025-49718
Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.
Sql Server 2019
15.0.2135.5 / 15.0.4435.7+
HIGH 7.5
CVE-2025-49719EPSS 11%
Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
Sql Server 2016
13.0.6460.7 / 13.0.7055.9+
MEDIUM 5.7
CVE-2025-49722
Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.8
CVE-2025-49705
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-49711
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20027+
HIGH 7.8
CVE-2025-49714
Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally.
Python
2025.8.1+
HIGH 7.5
CVE-2025-49716
Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+
MEDIUM 6.5
CVE-2025-49706 KEVEPSS 100%
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Sharepoint Enterprise Server
16.0.18526.20424+
HIGH 8.8
CVE-2025-49701
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
16.0.18526.20424+
HIGH 8.8
CVE-2025-49704 KEVEPSS 100%
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
Mitigation only
HIGH 7.8
CVE-2025-49702
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-49703
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2025-49697
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20027+
HIGH 7.8
CVE-2025-49698
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-49700
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only