Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2025-24996
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.8
CVE-2025-24993 KEV
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
MEDIUM 6.8
CVE-2025-24988
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
MEDIUM 5.5
CVE-2025-24991 KEV
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
MEDIUM 5.5
CVE-2025-24992
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.8
CVE-2025-24985 KEV
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
MEDIUM 6.8
CVE-2025-24987
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
MEDIUM 6.5
CVE-2025-24986
Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.
Azure Promptflow Core
1.6.0 / 1.17.2+
HIGH 8.4
CVE-2025-24084
Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.
Windows 11 22h2
10.0.20348.3270 / 10.0.22621.5039+
HIGH 7.8
CVE-2025-24082
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-24083
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.0
CVE-2025-24983 KEV
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.8
CVE-2025-24081
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-24079
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-24080
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-24072
Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.8
CVE-2025-24075
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-24077
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.3
CVE-2025-24076
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Windows 11 22h2
10.0.22621.5039 / 10.0.22631.5039+
HIGH 7.0
CVE-2025-24078
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.1
CVE-2025-24064
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
Windows Server 2008
10.0.14393.7876 / 10.0.17763.7009+
HIGH 7.8
CVE-2025-24066
Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.8
CVE-2025-24067
Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.0
CVE-2025-24070
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
Asp.net Core
8.0.14 / 9.0.3+
MEDIUM 6.5
CVE-2025-24071EPSS 25%
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a networ…
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 8.8
CVE-2025-24056
Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.8
CVE-2025-24057
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-24059
Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.8
CVE-2025-24061
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 8.8
CVE-2025-24051
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+