Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2025-32716
Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
MEDIUM 6.5
CVE-2025-32715
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Remote Desktop Client
1.2.6278 / 2.0.505.0+
HIGH 7.8
CVE-2025-32714
Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
HIGH 7.8
CVE-2025-32713
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
HIGH 7.8
CVE-2025-32712
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
HIGH 8.1
CVE-2025-32710
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
Windows Server 2008
10.0.14393.8066 / 10.0.17763.7314+
HIGH 8.1
CVE-2025-29828
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.
Windows 11 22h2
10.0.20348.3745 / 10.0.22621.5472+
MEDIUM 5.5
CVE-2025-24069
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
MEDIUM 5.5
CVE-2025-24068
Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
MEDIUM 5.5
CVE-2025-24065
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
CRITICAL 9.8
CVE-2025-47966
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.
Power Automate For Desktop
No fix yet
HIGH 8.8
CVE-2025-47181
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges…
Edge Update
1.3.195.61+
HIGH 7.8
CVE-2025-47161
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
Defender For Endpoint
101.25022.0002+
HIGH 8.0
CVE-2025-26646
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing ove…
Build Tools
8.0.16 / 9.0.5+
HIGH 7.8
CVE-2025-32709 KEV
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 7.8
CVE-2025-32704
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-32705
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-32706 KEV
Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 7.8
CVE-2025-32707
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
MEDIUM 5.5
CVE-2025-32703
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
Visual Studio 2017
15.9.73 / 16.11.47+
HIGH 7.8
CVE-2025-30393
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-30400 KEV
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7314 / 10.0.19044.5854+
HIGH 7.8
CVE-2025-32701 KEV
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 7.8
CVE-2025-32702
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code …
Visual Studio 2019
16.11.47 / 17.8.21+
HIGH 7.5
CVE-2025-30397 KEVEPSS 27%
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a ne…
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
MEDIUM 5.9
CVE-2025-30394EPSS 30%
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.
Windows Server 2012
10.0.14393.8066 / 10.0.17763.7314+
CRITICAL 9.8
CVE-2025-30387
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a …
Azure Ai Document Intelligence Studio
Mitigation only
HIGH 7.8
CVE-2025-30385
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8066 / 10.0.17763.7314+
HIGH 7.8
CVE-2025-30386
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.18827.20000+
HIGH 7.8
CVE-2025-30388
Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
365 Copilot
10.0.10240.21014 / 10.0.14393.8066+