Vulnerabilities
Tracked app vulnerabilities
8,497 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-62462
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-62461
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-62458
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2025-62457
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2025-62456
HIGH 8.8
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
|
CVE-2025-62455
HIGH 7.8
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
|
CVE-2025-62454
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2025-62221
HIGH 7.8
KEV
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2025-59517
HIGH 7.8
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
|
CVE-2025-59516
HIGH 7.8
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
|
CVE-2025-55233
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-54100
HIGH 7.8
PowerShell Remote Code Execution Vulnerability |
|
CVE-2025-12084
MEDIUM 5.3
Network 1 apps
When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Avail… |
|
CVE-2025-13837
LOW 5.5
Local 1 apps
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues |
|
CVE-2025-13836
MEDIUM 7.5
Network 1 apps
When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server… |
|
CVE-2025-11001
HIGH 7.8
Local 1 apps
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… |
|
CVE-2025-52331
MEDIUM 6.1
Network 1 apps
Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the … |
|
CVE-2025-60724
CRITICAL 9.8
Network 1 apps
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2025-65018
HIGH 7.1
LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read` |
|
CVE-2025-64720
HIGH 7.1
LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication |
|
CVE-2025-62452
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-62219
HIGH 7.0
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability |
|
CVE-2025-62218
HIGH 7.0
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability |
|
CVE-2025-62217
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-62215
HIGH 7.0
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-62213
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-62209
HIGH 5.5
Windows License Manager Information Disclosure Vulnerability |
|
CVE-2025-62208
HIGH 5.5
Windows License Manager Information Disclosure Vulnerability |
|
CVE-2025-60723
HIGH 6.3
DirectX Graphics Kernel Denial of Service Vulnerability |
|
CVE-2025-60721
HIGH 7.8
Windows Administrator Protection Elevation of Privilege Vulnerability |
|
CVE-2025-60720
HIGH 7.8
Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability |
|
CVE-2025-60719
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-60718
HIGH 7.8
Windows Administrator Protection Elevation of Privilege Vulnerability |
|
CVE-2025-60717
HIGH 7.0
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability |
|
CVE-2025-60716
CRITICAL 7.0
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-60715
HIGH 8.0
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-60714
HIGH 7.8
Windows OLE Remote Code Execution Vulnerability |
|
CVE-2025-60713
HIGH 7.8
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability |
|
CVE-2025-60710
HIGH 7.8
KEV
Host Process for Windows Tasks Elevation of Privilege Vulnerability |
|
CVE-2025-60709
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-60708
HIGH 6.5
Storvsp.sys Driver Denial of Service Vulnerability |
|
CVE-2025-60707
HIGH 7.8
Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability |
|
CVE-2025-60706
HIGH 5.5
Windows Hyper-V Information Disclosure Vulnerability |
|
CVE-2025-60705
HIGH 7.8
Windows Client-Side Caching Elevation of Privilege Vulnerability |
|
CVE-2025-60704
HIGH 7.5
Windows Kerberos Elevation of Privilege Vulnerability |
|
CVE-2025-60703
HIGH 7.8
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
|
CVE-2025-59515
HIGH 7.0
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability |
|
CVE-2025-59514
HIGH 7.8
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability |
|
CVE-2025-59513
HIGH 5.5
Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability |
|
CVE-2025-59512
HIGH 7.8
Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability |