CYBERSECURITYTRACKER
TRACKING7,183 stories in this site build1,510 vulnerability news stories in this site build
Vulnerabilities

September 2025 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 0 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 401 vulnerabilities across 401 returned patch records from 1 vendor. Filter the complete month, or browse the static page trail without JavaScript.

401all patch recordsClear filters15criticalShow these records0Microsoft exploitation detectedShow these records3Microsoft in the Known Exploited Vulnerabilities catalogShow these records111tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 1 of 3 · records 1 to 200 of 401

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-41244 ↗azl3 open-vm-tools 12.3.5-2 on Azure Linux 3.0ImportantOut-of-band8%Microsoft rating unavailableCISA KEVVulnCheckENISAVMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
CVE-2025-39682 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-band1%Microsoft rating unavailableCISA KEVVulnCheckENISA1 mentionstls: fix handling of zero-length records on the rx_list
CVE-2025-10585 ↗Microsoft Edge (Chromium-based)N/AOut-of-band5%Microsoft rating unavailableCISA KEVVulnCheckENISAChromium: CVE-2025-10585 Type Confusion in V8
CVE-2025-53799 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Imaging Component Information Disclosure Vulnerability
CVE-2025-53800 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 7 moreKB5065426KB5065427KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-54910 ↗Microsoft Office 2019 for 32-bit editionsCritical1%Microsoft rates: Exploitation Less LikelyKB5002781Microsoft Office Remote Code Execution Vulnerability
CVE-2025-54918 ↗Windows 10 Version 1809 for 32-bit SystemsCritical19%Microsoft rates: Exploitation More LikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows NTLM Elevation of Privilege Vulnerability
CVE-2025-55224 ↗Windows 10 Version 1809 for x64-based SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2025-55226 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Graphics Kernel Remote Code Execution Vulnerability
CVE-2025-55228 ↗Windows Server 2022Critical0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 5 moreKB5065426KB5065429KB5065431KB5065432KB5065474
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2025-55236 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Graphics Kernel Remote Code Execution Vulnerability
CVE-2025-54914 ↗Azure NetworkingCriticalOut-of-band2%Microsoft rates: N/AAzure Networking Elevation of Privilege Vulnerability
CVE-2025-55238 ↗Dynamics 365 FastTrack ImplementationCriticalOut-of-band1%Microsoft rating unavailableDynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
CVE-2025-55241 ↗Microsoft Entra IDCriticalOut-of-band2%Microsoft rates: N/AAzure Entra ID Elevation of Privilege Vulnerability
CVE-2025-55242 ↗Xbox Gaming ServicesCriticalOut-of-band1%Microsoft rating unavailableXbox Certification Bug Copilot Djando Information Disclosure Vulnerability
CVE-2025-55244 ↗Azure Bot ServiceCriticalOut-of-band1%Microsoft rates: N/AAzure Bot Service Elevation of Privilege Vulnerability
CVE-2025-39743 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablejfs: truncate good inode pages when hard link is 0
CVE-2025-57052 ↗azl3 ceph 18.2.2-10 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablecJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.
CVE-2025-59251 ↗Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft rating unavailableMicrosoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2025-55322 ↗OmniParserImportantOut-of-band0%Microsoft rates: Exploitation Less LikelyOmniParser Remote Code Execution Vulnerability
CVE-2025-59215 ↗Windows Server 2025 (Server Core installation)ImportantOut-of-band0%Microsoft rates: Exploitation Less LikelyKB5065426KB5065474Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-59216 ↗Windows Server 2025 (Server Core installation)ImportantOut-of-band0%Microsoft rates: Exploitation Less LikelyKB5065426KB5065474Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-59220 ↗Windows Server 2022ImportantOut-of-band0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 5 moreKB5065426KB5065429KB5065431KB5065432KB5065474
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2025-49728 ↗Microsoft PC ManagerImportantOut-of-band0%Microsoft rates: Exploitation UnlikelyMicrosoft PC Manager Security Feature Bypass Vulnerability
CVE-2025-55319 ↗Visual Studio CodeImportantOut-of-band1%Microsoft rates: Exploitation More LikelyAgentic AI and Visual Studio Code Remote Code Execution Vulnerability
CVE-2025-47997 ↗Microsoft SQL Server 2017 for x64-based Systems (GDR)Important1%Microsoft rates: Exploitation Less LikelyKB5065220KB5065221
and 6 moreKB5065222KB5065223KB5065224KB5065225KB5065226KB5065227
Microsoft SQL Server Information Disclosure Vulnerability
CVE-2025-49692 ↗Azure Connected Machine AgentImportant0%Microsoft rates: Exploitation UnlikelyAzure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2025-49734 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 7 moreKB5065426KB5065427KB5065428KB5065429KB5065431KB5065432KB5065474
PowerShell Direct Elevation of Privilege Vulnerability
CVE-2025-53796 ↗Windows Server 2019Important1%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53797 ↗Windows Server 2019Important1%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53798 ↗Windows Server 2019Important1%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53801 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 6 moreKB5065427KB5065428KB5065429KB5065430KB5065431KB5065432
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-53802 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 5 moreKB5065426KB5065429KB5065431KB5065432KB5065474
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2025-53803 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation More LikelyKB5065306KB5065425
and 10 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474KB5065507KB5065509
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2025-53804 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation More LikelyKB5065306KB5065425
and 10 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474KB5065507KB5065509
Windows Kernel-Mode Driver Information Disclosure Vulnerability
CVE-2025-53805 ↗Windows Server 2022Important1%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 4 moreKB5065426KB5065431KB5065432KB5065474
HTTP.sys Denial of Service Vulnerability
CVE-2025-53806 ↗Windows Server 2019Important1%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53807 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-53808 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-53809 ↗Windows Server 2025 (Server Core installation)Important1%Microsoft rates: Exploitation Less LikelyKB5065426KB5065474Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2025-53810 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54091 ↗Windows 10 Version 1809 for x64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 10 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474KB5065507KB5065509
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-54092 ↗Windows 10 Version 1809 for x64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-54093 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation More LikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows TCP/IP Driver Elevation of Privilege Vulnerability
CVE-2025-54094 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54095 ↗Windows Server 2019Important1%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-54096 ↗Windows Server 2019Important1%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-54097 ↗Windows Server 2019Important1%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-54098 ↗Windows 10 Version 1809 for x64-based SystemsImportant3%Microsoft rates: Exploitation More LikelyKB5065306KB5065425
and 12 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065509KB5065510
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-54099 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-54101 ↗Windows 10 Version 1809 for 32-bit SystemsImportant2%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 8 moreKB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065507KB5065509
Windows SMB Client Remote Code Execution Vulnerability
CVE-2025-54102 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 7 moreKB5065426KB5065427KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2025-54103 ↗Windows 10 Version 21H2 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065425KB5065426
and 3 moreKB5065429KB5065431KB5065474
Windows Management Service Elevation of Privilege Vulnerability
CVE-2025-54104 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54105 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5065425KB5065426
and 1 moreKB5065474
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-54106 ↗Windows Server 2019Important1%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 6 moreKB5065426KB5065427KB5065428KB5065432KB5065474KB5065507
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-54107 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 15 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065435KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-54108 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation UnlikelyKB5065426KB5065474Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2025-54109 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54110 ↗Windows 10 Version 1809 for 32-bit SystemsImportant4%Microsoft rates: Exploitation More LikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-54111 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 8 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474
Windows UI XAML Phone DatePickerFlyout Elevation of Privilege Vulnerability
CVE-2025-54112 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 8 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
CVE-2025-54113 ↗Windows Server 2019Important1%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-54114 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 6 moreKB5065426KB5065427KB5065429KB5065431KB5065432KB5065474
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2025-54115 ↗Windows 10 Version 1809 for x64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-54116 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 8 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474
Windows MultiPoint Services Elevation of Privilege Vulnerability
CVE-2025-54894 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
CVE-2025-54895 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 12 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065509KB5065510
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability
CVE-2025-54896 ↗Office Online ServerImportant1%Microsoft rates: Exploitation UnlikelyKB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54897 ↗Microsoft SharePoint Enterprise Server 2016Important19%Microsoft rates: Exploitation Less LikelyKB5002775KB5002778
and 1 moreKB5002784
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2025-54898 ↗Office Online ServerImportant1%Microsoft rates: Exploitation Less LikelyKB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54899 ↗Microsoft Office 2019 for 32-bit editionsImportant1%Microsoft rates: Exploitation UnlikelyKB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54900 ↗Office Online ServerImportant1%Microsoft rates: Exploitation UnlikelyKB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54901 ↗Microsoft Office 2019 for 32-bit editionsImportant1%Microsoft rates: Exploitation Less LikelyKB5002762Microsoft Excel Information Disclosure Vulnerability
CVE-2025-54902 ↗Office Online ServerImportant1%Microsoft rates: Exploitation Less LikelyKB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54903 ↗Office Online ServerImportant1%Microsoft rates: Exploitation Less LikelyKB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54904 ↗Office Online ServerImportant1%Microsoft rates: Exploitation Less LikelyKB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54905 ↗Microsoft SharePoint Enterprise Server 2016Important1%Microsoft rates: Exploitation Less LikelyKB5002774KB5002775
and 3 moreKB5002777KB5002778KB5002780
Microsoft Word Information Disclosure Vulnerability
CVE-2025-54906 ↗Microsoft SharePoint Enterprise Server 2016Important1%Microsoft rates: Exploitation Less LikelyKB5002576KB5002766
and 3 moreKB5002775KB5002778KB5002781
Microsoft Office Remote Code Execution Vulnerability
CVE-2025-54907 ↗Microsoft Office 2019 for 32-bit editionsImportant1%Microsoft rates: Exploitation Less LikelyMicrosoft Office Visio Remote Code Execution Vulnerability
CVE-2025-54908 ↗Microsoft Office 2019 for 32-bit editionsImportant1%Microsoft rates: Exploitation Less LikelyKB5002779Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2025-54911 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 12 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065509KB5065510
Windows BitLocker Elevation of Privilege Vulnerability
CVE-2025-54912 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 12 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065509KB5065510
Windows BitLocker Elevation of Privilege Vulnerability
CVE-2025-54913 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 8 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474
Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability
CVE-2025-54915 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54916 ↗Windows 10 Version 1809 for 32-bit SystemsImportant2%Microsoft rates: Exploitation More LikelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows NTFS Remote Code Execution Vulnerability
CVE-2025-54917 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 15 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065435KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-54919 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2025-55223 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-55225 ↗Windows Server 2019Important1%Microsoft rates: Exploitation Less LikelyKB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-55227 ↗Microsoft SQL Server 2017 for x64-based Systems (GDR)Important1%Microsoft rates: Exploitation Less LikelyKB5065220KB5065221
and 6 moreKB5065222KB5065223KB5065224KB5065225KB5065226KB5065227
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-55232 ↗Microsoft HPC Pack 2019Important2%Microsoft rates: Exploitation Less LikelyMicrosoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
CVE-2025-55234 ↗Windows 10 Version 1809 for 32-bit SystemsImportant20%Microsoft rates: Exploitation More LikelyPublicly disclosedKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows SMB Elevation of Privilege Vulnerability
CVE-2025-55243 ↗Microsoft OfficePLUSImportant1%Microsoft rates: Exploitation Less LikelyMicrosoft OfficePlus Spoofing Vulnerability
CVE-2025-55245 ↗Xbox Gaming ServicesImportant0%Microsoft rates: Exploitation Less LikelyXbox Gaming Services Elevation of Privilege Vulnerability
CVE-2025-55316 ↗Azure Connected Machine AgentImportant0%Microsoft rates: Exploitation UnlikelyAzure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2025-55317 ↗Microsoft AutoUpdate for MacImportant0%Microsoft rates: Exploitation UnlikelyMicrosoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
CVE-2025-39806 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableHID: multitouch: fix slab out-of-bounds access in mt_report_fixup()
CVE-2022-50406 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableiomap: iomap: fix memory corruption when recording errors during writeback
CVE-2023-53254 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablecacheinfo: Fix shared_cpu_map to handle shared caches at different levels
CVE-2023-53218 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablerxrpc: Make it so that a waiting process can be aborted
CVE-2023-53187 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebtrfs: fix use-after-free of new block group that became unused
CVE-2025-55552 ↗azl3 pytorch 2.2.2-7 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablepytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are used together.
CVE-2025-55551 ↗azl3 pytorch 2.2.2-7 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableAn issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
CVE-2025-9648 ↗azl3 ceph 18.2.2-10 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableDenial of Service in CivetWeb
CVE-2025-9230 ↗azl3 openssl 3.3.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableOut-of-bounds read & write in RFC 3211 KEK Unwrap
CVE-2025-55557 ↗cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableA Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading to a Denial of Service (DoS).
CVE-2025-55553 ↗cbl2 pytorch 2.0.0-9 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableA syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
CVE-2025-11021 ↗cbl2 libsoup 3.0.4-9 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableLibsoup: out-of-bounds read in cookie date handling of libsoup http library
CVE-2025-59362 ↗azl3 squid 6.13-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableSquid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c.
CVE-2025-9900 ↗cbl2 libtiff 4.6.0-8 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableLibtiff: libtiff write-what-where
CVE-2025-39883 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory
CVE-2025-39873 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablecan: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB
CVE-2025-39866 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablefs: writeback: fix use-after-free in __mark_inode_dirty()
CVE-2025-39864 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: cfg80211: fix use-after-free in cmp_bss()
CVE-2025-39861 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableBluetooth: vhci: Prevent use-after-free by removing debugfs files early
CVE-2025-39850 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablevxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objects
CVE-2025-39863 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work
CVE-2025-39860 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableBluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()
CVE-2025-39865 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabletee: fix NULL pointer dereference in tee_shm_put
CVE-2025-39841 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablescsi: lpfc: Fix buffer free/clear order in deferred receive path
CVE-2025-39851 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablevxlan: Fix NPD when refreshing an FDB entry with a nexthop object
CVE-2025-39853 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablei40e: Fix potential invalid access when MAC list is empty
CVE-2025-39843 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemm: slub: avoid wake up kswapd in set_track_prepare
CVE-2025-39839 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebatman-adv: fix OOB read/write in network-coding decode
CVE-2025-39824 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableHID: asus: fix UAF via HID_CLAIMED_INPUT validation
CVE-2025-39823 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableKVM: x86: use array_index_nospec with indices that come from guest
CVE-2025-39833 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemISDN: hfcpci: Fix warning when deleting uninitialized timer
CVE-2025-39832 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5: Fix lockdep assertion on sync reset unload event
CVE-2025-39817 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableefivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
CVE-2025-39828 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableatm: atmtcp: Prevent arbitrary write in atmtcp_recv_control().
CVE-2025-39825 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablesmb: client: fix race with concurrent opens in rename(2)
CVE-2025-39835 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablexfs: do not propagate ENODATA disk errors into xattr code
CVE-2025-9906 ↗azl3 keras 3.3.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableArbitrary Code execution in Keras Safe Mode
CVE-2025-9905 ↗azl3 keras 3.3.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableArbitary Code execution in Keras load_model()
CVE-2025-39810 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebnxt_en: Fix memory corruption when FW resources change during ifdown
CVE-2025-58754 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableAxios is vulnerable to DoS attack through lack of data size check
CVE-2025-39776 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemm/debug_vm_pgtable: clear page table entries at destroy_args()
CVE-2025-39738 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebtrfs: do not allow relocation of partially dropped subvolumes
CVE-2025-39790 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebus: mhi: host: Detect events pointing to unexpected TREs
CVE-2025-39766 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenet/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit
CVE-2025-39757 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableALSA: usb-audio: Validate UAC3 cluster segment descriptors
CVE-2025-39742 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableRDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask()
CVE-2025-39761 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: ath12k: Decrement TID on RX peer frag setup error handling
CVE-2025-39759 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebtrfs: qgroup: fix race between quota disable and quota rescan ioctl
CVE-2025-39751 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableALSA: hda/ca0132: Fix buffer overflow in add_tuning_control
CVE-2025-39746 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: ath10k: shutdown driver when hardware is unreliable
CVE-2025-39750 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: ath12k: Correct tid cleanup when tid setup fails
CVE-2025-39749 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablercu: Protect ->defer_qs_iw_pending from data race
CVE-2025-39788 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablescsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE
CVE-2025-58060 ↗azl3 cups 2.4.10-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablecups has Authentication bypass with AuthType Negotiate
CVE-2025-58063 ↗azl3 coredns 1.11.4-8 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableCoreDNS: DNS Cache Pinning via etcd Lease ID Confusion
CVE-2025-40928 ↗cbl2 perl-JSON-XS 4.03-2 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableJSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
CVE-2025-39730 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantNot availableMicrosoft rating unavailableNFS: Fix filehandle bounds checking in nfs_fh_to_dentry()
CVE-2025-39732 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantNot availableMicrosoft rating unavailablewifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask()
CVE-2025-9566 ↗azl3 libcontainers-common 20240213-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablePodman: podman kube play command may overwrite host files
CVE-2025-39683 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabletracing: Limit access to parser->buffer when trace_get_user failed
CVE-2025-39713 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemedia: rainshadow-cec: fix TOCTOU race condition in rain_interrupt()
CVE-2025-39691 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablefs/buffer: fix use-after-free when call bh_read() helper
CVE-2025-38732 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nf_reject: don't leak dst refcount for loopback packets
CVE-2025-39673 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableppp: fix race conditions in ppp_fill_forward_path
CVE-2025-39694 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailables390/sclp: Fix SCCB present check
CVE-2025-39721 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablecrypto: qat - flush misc workqueue during device shutdown
CVE-2025-39711 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemedia: ivsc: Fix crash at shutdown due to missing mei_cldev_disable() calls
CVE-2025-39689 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableftrace: Also allocate and copy hash for reading of filter files
CVE-2025-38735 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablegve: prevent ethtool ops after shutdown
CVE-2025-39702 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableipv6: sr: Fix MAC comparison to be constant-time
CVE-2025-38692 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableexfat: add cluster chain loop check for dir
CVE-2025-38703 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/xe: Make dma-fences compliant with the safe access rules
CVE-2025-38728 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablesmb3: fix for slab out of bounds on mount to ksmbd
CVE-2025-38679 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemedia: venus: Fix OOB read due to missing payload bound check
CVE-2025-38702 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablefbdev: fix potential buffer overflow in do_register_framebuffer()
CVE-2025-38724 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
CVE-2025-38699 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablescsi: bfa: Double-free fix
CVE-2025-38684 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenet/sched: ets: use old 'nbands' while purging unused classes
CVE-2025-38697 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablejfs: upper bound check of tree index in dbAllocAG
CVE-2025-38714 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablehfsplus: fix slab-out-of-bounds in hfsplus_bnode_read()
CVE-2025-38680 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemedia: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()
CVE-2025-38729 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableALSA: usb-audio: Validate UAC3 power domain descriptors, too
CVE-2025-38685 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablefbdev: Fix vmalloc out-of-bounds write in fast_imageblit
CVE-2025-38718 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablesctp: linearize cloned gso packets in sctp_rcv
CVE-2025-38688 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableiommufd: Prevent ALIGN() overflow
CVE-2025-47906 ↗azl3 golang 1.24.5-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableUnexpected paths returned from LookPath in os/exec
CVE-2025-39800 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-band0%Microsoft rating unavailablebtrfs: abort transaction on unexpected eb generation at btrfs_copy_root()
CVE-2025-53791 ↗Microsoft Edge (Chromium-based)ModerateOut-of-band0%Microsoft rates: Exploitation Less LikelyMicrosoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2025-39782 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablejbd2: prevent softlockup in jbd2_log_do_checkpoint()
CVE-2025-39770 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM
CVE-2022-50327 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableACPI: processor: idle: Check acpi_fetch_acpi_dev() return value
CVE-2025-39734 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRevert "fs/ntfs3: Replace inode_trylock with inode_lock"
CVE-2025-38693 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemedia: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar
CVE-2025-38683 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablehv_netvsc: Fix panic during namespace deletion with VF
CVE-2024-58241 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_core: Disable works on hci_unregister_dev
CVE-2023-53447 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablef2fs: don't reset unchangable mount option in f2fs_remount()
CVE-2023-53376 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: mpi3mr: Use number of bits to manage bitmap sizes
CVE-2023-53371 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5e: fix memory leak in mlx5e_fs_tt_redirect_any_create
CVE-2023-53370 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: fix memory leak in mes self test
CVE-2022-50418 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: ath11k: mhi: fix potential memory leak in ath11k_mhi_register()
CVE-2022-50393 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: SDMA update use unlocked iterator
CVE-2022-50390 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/ttm: fix undefined behavior in bit shift for TTM_TT_FLAG_PRIV_POPULATED
CVE-2023-53401 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm: kmem: fix a NULL pointer dereference in obj_stock_flush_required()

Glossary