Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.0
CVE-2025-49699
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 8.4
CVE-2025-49695
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2025-49696
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.0
CVE-2025-49691
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.8
CVE-2025-49693
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Windows 11 22h2
10.0.22621.5624 / 10.0.22631.5624+
HIGH 7.8
CVE-2025-49694
Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.25398.1732 / 10.0.26100.4652+
HIGH 8.8
CVE-2025-49687
Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 8.8
CVE-2025-49688
Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Windows Server 2012
10.0.14393.8246 / 10.0.17763.7558+
HIGH 7.8
CVE-2025-49686
Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.8
CVE-2025-49689
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.4
CVE-2025-49690
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a…
Windows 10 1809
10.0.17763.7558 / 10.0.19044.6093+
HIGH 7.8
CVE-2025-49683
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.3
CVE-2025-49682
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
Windows 10 21h2
10.0.19044.6093 / 10.0.19045.6093+
HIGH 7.0
CVE-2025-49685
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7558 / 10.0.19044.6093+
MEDIUM 6.5
CVE-2025-49681
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+
MEDIUM 5.5
CVE-2025-49684
Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 8.8
CVE-2025-49676
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+
HIGH 7.8
CVE-2025-49679
Numeric truncation error in Windows Shell allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.3
CVE-2025-49680
Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.0
CVE-2025-49677
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Windows 11 22h2
10.0.22621.5624+
HIGH 7.0
CVE-2025-49678
Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 8.8
CVE-2025-49672
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+
HIGH 8.8
CVE-2025-49673
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+
HIGH 8.8
CVE-2025-49674
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+
HIGH 7.8
CVE-2025-49675
Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 8.8
CVE-2025-49668
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+
HIGH 8.8
CVE-2025-49669
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+
HIGH 7.8
CVE-2025-49667
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
MEDIUM 6.5
CVE-2025-49670
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+
MEDIUM 6.5
CVE-2025-49671
Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis…
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+