Vulnerabilities
Tracked app vulnerabilities
11,275 CVEs affect a tracked app or OS (High, all platforms). 229 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 11,275
- Actively exploited
- 229
- Publication window
- 2010-07-30 → 2026-08-19
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-64658
HIGH 7.5
Windows File Explorer Elevation of Privilege Vulnerability |
|
CVE-2025-62573
HIGH 7.0
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-62572
HIGH 7.8
Application Information Service Elevation of Privilege Vulnerability |
|
CVE-2025-62571
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2025-62570
HIGH 7.1
Windows Camera Frame Server Monitor Information Disclosure Vulnerability |
|
CVE-2025-62569
HIGH 7.0
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-62567
HIGH 5.3
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2025-62565
HIGH 7.3
Windows File Explorer Elevation of Privilege Vulnerability |
|
CVE-2025-62549
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-62474
HIGH 7.8
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2025-62473
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-62472
HIGH 7.8
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2025-62470
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-62469
HIGH 7.0
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-62468
HIGH 5.5
Windows Defender Firewall Service Information Disclosure Vulnerability |
|
CVE-2025-62467
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-62466
HIGH 7.8
Windows Client-Side Caching Elevation of Privilege Vulnerability |
|
CVE-2025-62465
HIGH 6.5
DirectX Graphics Kernel Denial of Service Vulnerability |
|
CVE-2025-62464
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-62463
HIGH 6.5
DirectX Graphics Kernel Denial of Service Vulnerability |
|
CVE-2025-62462
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-62461
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-62458
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2025-62457
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2025-62456
HIGH 8.8
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
|
CVE-2025-62455
HIGH 7.8
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
|
CVE-2025-62454
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2025-62221
HIGH 7.8
KEV
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2025-59517
HIGH 7.8
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
|
CVE-2025-59516
HIGH 7.8
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
|
CVE-2025-55233
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-54100
HIGH 7.8
PowerShell Remote Code Execution Vulnerability |
|
CVE-2025-48615
HIGH 7.8
In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local escalatio… |
|
CVE-2025-48612
HIGH 7.8
In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to improper … |
|
CVE-2025-48566
HIGH 7.8
In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input validation. This could lead to local e… |
|
CVE-2025-48565
HIGH 7.8
In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the code. This could lead to local escalation … |
|
CVE-2025-48564
HIGH 7.0
In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escalation of privilege with no additional ex… |
|
CVE-2025-40266
HIGH 8.2
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memory share Verify the offset to prevent … |
|
CVE-2025-40214
HIGH 7.8
In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC c… |
|
CVE-2025-8045
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-6573
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-6349
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61619
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61618
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61617
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61610
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61609
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61608
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-61607
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-58410
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |