CYBERSECURITYTRACKER
TRACKING3,612 stories653 vuln stories
Patch Day month

September 2025 vulnerabilities

A server-rendered hunting trail for September 2025: 401 returned patch records across 1 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.

401all patches
15critical
0exploitation detected
2in CISA KEV
109tracked here
Microsoft 401

Page 2 of 3 · records 201–400 of 401

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-39758 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandRDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages
CVE-2025-39760 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandusb: core: config: Prevent OOB read in SS endpoint companion parsing
CVE-2025-39781 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandparisc: Drop WARN_ON_ONCE() from flush_cache_vmap
CVE-2025-39788 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandscsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE
CVE-2025-39756 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandfs: Prevent file descriptor table allocations exceeding INT_MAX
CVE-2025-39745 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandrcutorture: Fix rcutorture_one_extend_check() splat in RT kernels
CVE-2025-39783 ↗2025-09-13azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandPCI: endpoint: Fix configfs group list head handling
CVE-2025-58364 ↗2025-09-12cbl2 cups 2.3.3-9 on CBL Mariner 2.0ModerateOut-of-bandcups: Remote DoS via null dereference
CVE-2025-48039 ↗2025-09-12azl3 erlang 26.2.5.13-1 on Azure Linux 3.0ModerateOut-of-bandUnverified Paths can Cause Excessive Use of System Resources
CVE-2025-48041 ↗2025-09-12azl3 erlang 26.2.5.13-1 on Azure Linux 3.0ModerateOut-of-bandSSH_FXP_OPENDIR may Lead to Exhaustion of File Handles
CVE-2025-48038 ↗2025-09-12azl3 erlang 26.2.5.13-1 on Azure Linux 3.0ModerateOut-of-bandUnverified File Handles can Cause Excessive Use of System Resources
CVE-2025-58060 ↗2025-09-12azl3 cups 2.4.10-1 on Azure Linux 3.0ImportantOut-of-bandcups has Authentication bypass with AuthType Negotiate
CVE-2025-10201 ↗2025-09-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-10201 Inappropriate implementation in Mojo
CVE-2025-10200 ↗2025-09-11Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2025-10200 Use after free in Serviceworker
CVE-2025-55319 ↗2025-09-11Visual Studio CodeImportantOut-of-band1%More likelyAgentic AI and Visual Studio Code Remote Code Execution Vulnerability
CVE-2025-58063 ↗2025-09-11azl3 coredns 1.11.4-7 on Azure Linux 3.0ImportantOut-of-bandCoreDNS: DNS Cache Pinning via etcd Lease ID Confusion
CVE-2025-8277 ↗2025-09-11cbl2 libssh 0.10.6-2 on CBL Mariner 2.0LowOut-of-bandLibssh: memory exhaustion via repeated key exchange in libssh
CVE-2025-10148 ↗2025-09-11azl3 curl 8.11.1-3 on Azure Linux 3.0ModerateOut-of-bandpredictable WebSocket mask
CVE-2025-40928 ↗2025-09-11cbl2 perl-JSON-XS 4.03-2 on CBL Mariner 2.0ImportantOut-of-bandJSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
CVE-2025-39730 ↗2025-09-09azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantNFS: Fix filehandle bounds checking in nfs_fh_to_dentry()
CVE-2025-39732 ↗2025-09-09azl3 kernel 6.6.96.2-1 on Azure Linux 3.0Importantwifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask()
CVE-2025-39731 ↗2025-09-09azl3 kernel 6.6.96.2-1 on Azure Linux 3.0Moderatef2fs: vm_unmap_ram() may be called from an invalid context
CVE-2024-21907 ↗2025-09-09Microsoft SQL Server 2017 for x64-based Systems (GDR)N/A33%KB5065222KB5065223
and 4 moreKB5065224KB5065225KB5065226KB5065227
VulnCheck: CVE-2024-21907 Improper Handling of Exceptional Conditions in Newtonsoft.Json
CVE-2025-47997 ↗2025-09-09Microsoft SQL Server 2017 for x64-based Systems (GDR)Important1%KB5065220KB5065221
and 6 moreKB5065222KB5065223KB5065224KB5065225KB5065226KB5065227
Microsoft SQL Server Information Disclosure Vulnerability
CVE-2025-49692 ↗2025-09-09Azure Connected Machine AgentImportant0%Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2025-49734 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 7 moreKB5065426KB5065427KB5065428KB5065429KB5065431KB5065432KB5065474
PowerShell Direct Elevation of Privilege Vulnerability
CVE-2025-53796 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53797 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53798 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53799 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Imaging Component Information Disclosure Vulnerability
CVE-2025-53800 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5065306KB5065425
and 7 moreKB5065426KB5065427KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-53801 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 6 moreKB5065427KB5065428KB5065429KB5065430KB5065431KB5065432
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-53802 ↗2025-09-09Windows Server 2022Important0%KB5065306KB5065425
and 5 moreKB5065426KB5065429KB5065431KB5065432KB5065474
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2025-53803 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant1%More likelyKB5065306KB5065425
and 10 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474KB5065507KB5065509
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2025-53804 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant1%More likelyKB5065306KB5065425
and 10 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474KB5065507KB5065509
Windows Kernel-Mode Driver Information Disclosure Vulnerability
CVE-2025-53805 ↗2025-09-09Windows Server 2022Important1%KB5065306KB5065425
and 4 moreKB5065426KB5065431KB5065432KB5065474
HTTP.sys Denial of Service Vulnerability
CVE-2025-53806 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-53807 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2025-53808 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-53809 ↗2025-09-09Windows Server 2025 (Server Core installation)Important1%KB5065426KB5065474Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
CVE-2025-53810 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54091 ↗2025-09-09Windows 10 Version 1809 for x64-based SystemsImportant0%KB5065306KB5065425
and 10 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474KB5065507KB5065509
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-54092 ↗2025-09-09Windows 10 Version 1809 for x64-based SystemsImportant0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-54093 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows TCP/IP Driver Elevation of Privilege Vulnerability
CVE-2025-54094 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54095 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-54096 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-54097 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-54098 ↗2025-09-09Windows 10 Version 1809 for x64-based SystemsImportant3%More likelyKB5065306KB5065425
and 12 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065509KB5065510
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-54099 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-54101 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant2%KB5065306KB5065425
and 8 moreKB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065507KB5065509
Windows SMB Client Remote Code Execution Vulnerability
CVE-2025-54102 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 7 moreKB5065426KB5065427KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2025-54103 ↗2025-09-09Windows 10 Version 21H2 for 32-bit SystemsImportant0%KB5065425KB5065426
and 3 moreKB5065429KB5065431KB5065474
Windows Management Service Elevation of Privilege Vulnerability
CVE-2025-54104 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54105 ↗2025-09-09Windows Server 2025 (Server Core installation)Important0%KB5065425KB5065426
and 1 moreKB5065474
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-54106 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 6 moreKB5065426KB5065427KB5065428KB5065432KB5065474KB5065507
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-54107 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5065306KB5065425
and 15 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065435KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-54108 ↗2025-09-09Windows Server 2025 (Server Core installation)Important0%KB5065426KB5065474Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
CVE-2025-54109 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54110 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant4%More likelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-54111 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 8 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474
Windows UI XAML Phone DatePickerFlyout Elevation of Privilege Vulnerability
CVE-2025-54112 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 8 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
CVE-2025-54113 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-54114 ↗2025-09-09Windows Server 2022Important0%KB5065306KB5065425
and 6 moreKB5065426KB5065427KB5065429KB5065431KB5065432KB5065474
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2025-54115 ↗2025-09-09Windows 10 Version 1809 for x64-based SystemsImportant0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2025-54116 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 8 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474
Windows MultiPoint Services Elevation of Privilege Vulnerability
CVE-2025-54894 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
CVE-2025-54895 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 12 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065509KB5065510
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability
CVE-2025-54896 ↗2025-09-09Office Online ServerImportant1%KB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54897 ↗2025-09-09Microsoft SharePoint Enterprise Server 2016Important18%KB5002775KB5002778
and 1 moreKB5002784
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2025-54898 ↗2025-09-09Office Online ServerImportant1%KB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54899 ↗2025-09-09Microsoft Office 2019 for 32-bit editionsImportant1%KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54900 ↗2025-09-09Office Online ServerImportant1%KB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54901 ↗2025-09-09Microsoft Office 2019 for 32-bit editionsImportant1%KB5002762Microsoft Excel Information Disclosure Vulnerability
CVE-2025-54902 ↗2025-09-09Office Online ServerImportant1%KB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54903 ↗2025-09-09Office Online ServerImportant1%KB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54904 ↗2025-09-09Office Online ServerImportant1%KB5002776KB5002782Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-54905 ↗2025-09-09Microsoft SharePoint Enterprise Server 2016Important1%KB5002774KB5002775
and 3 moreKB5002777KB5002778KB5002780
Microsoft Word Information Disclosure Vulnerability
CVE-2025-54906 ↗2025-09-09Microsoft SharePoint Enterprise Server 2016Important1%KB5002576KB5002766
and 3 moreKB5002775KB5002778KB5002781
Microsoft Office Remote Code Execution Vulnerability
CVE-2025-54907 ↗2025-09-09Microsoft Office 2019 for 32-bit editionsImportant0%Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2025-54908 ↗2025-09-09Microsoft Office 2019 for 32-bit editionsImportant1%KB5002779Microsoft PowerPoint Remote Code Execution Vulnerability
CVE-2025-54910 ↗2025-09-09Microsoft Office 2019 for 32-bit editionsCritical1%KB5002781Microsoft Office Remote Code Execution Vulnerability
CVE-2025-54911 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5065306KB5065425
and 12 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065509KB5065510
Windows BitLocker Elevation of Privilege Vulnerability
CVE-2025-54912 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 12 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065509KB5065510
Windows BitLocker Elevation of Privilege Vulnerability
CVE-2025-54913 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 8 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065474
Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability
CVE-2025-54915 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54916 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows NTFS Remote Code Execution Vulnerability
CVE-2025-54917 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5065306KB5065425
and 15 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065435KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-54918 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsCritical19%More likelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows NTLM Elevation of Privilege Vulnerability
CVE-2025-54919 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2025-55223 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-55224 ↗2025-09-09Windows 10 Version 1809 for x64-based SystemsCritical0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2025-55225 ↗2025-09-09Windows Server 2019Important1%KB5065306KB5065425
and 11 moreKB5065426KB5065427KB5065428KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-55226 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Graphics Kernel Remote Code Execution Vulnerability
CVE-2025-55227 ↗2025-09-09Microsoft SQL Server 2017 for x64-based Systems (GDR)Important1%KB5065220KB5065221
and 6 moreKB5065222KB5065223KB5065224KB5065225KB5065226KB5065227
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-55228 ↗2025-09-09Windows Server 2022Critical0%KB5065306KB5065425
and 5 moreKB5065426KB5065429KB5065431KB5065432KB5065474
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2025-55232 ↗2025-09-09Microsoft HPC Pack 2019Important2%Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
CVE-2025-55234 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsImportant19%More likelyKB5065306KB5065425
and 14 moreKB5065426KB5065427KB5065428KB5065429KB5065430KB5065431KB5065432KB5065468KB5065474KB5065507KB5065508KB5065509KB5065510KB5065511
Windows SMB Elevation of Privilege Vulnerability
CVE-2025-55236 ↗2025-09-09Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5065306KB5065425
and 6 moreKB5065426KB5065428KB5065429KB5065431KB5065432KB5065474
Graphics Kernel Remote Code Execution Vulnerability
CVE-2025-55243 ↗2025-09-09Microsoft OfficePLUSImportant1%Microsoft OfficePlus Spoofing Vulnerability
CVE-2025-55245 ↗2025-09-09Xbox Gaming ServicesImportant0%Xbox Gaming Services Elevation of Privilege Vulnerability
CVE-2025-55316 ↗2025-09-09Azure Connected Machine AgentImportant0%Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2025-55317 ↗2025-09-09Microsoft AutoUpdate for MacImportant0%Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
CVE-2025-9901 ↗2025-09-07azl3 libsoup 3.4.4-9 on Azure Linux 3.0ModerateOut-of-bandLibsoup: improper handling of http vary header in libsoup caching
CVE-2025-9566 ↗2025-09-07azl3 libcontainers-common 20240213-3 on Azure Linux 3.0ImportantOut-of-bandPodman: podman kube play command may overwrite host files
CVE-2025-57052 ↗2025-09-07azl3 ceph 18.2.2-10 on Azure Linux 3.0CriticalOut-of-bandcJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking and access restricted data via malformed JSON pointer strings containing alphanumeric characters.
CVE-2025-39681 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandx86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init helper
CVE-2025-38736 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnet: usb: asix_devices: Fix PHY address mask in MDIO bus initialization
CVE-2025-39683 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandtracing: Limit access to parser->buffer when trace_get_user failed
CVE-2025-39676 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandscsi: qla4xxx: Prevent a potential error pointer dereference
CVE-2025-39679 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/nouveau/nvif: Fix potential memory leak in nvif_vmm_ctor().
CVE-2025-39713 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandmedia: rainshadow-cec: fix TOCTOU race condition in rain_interrupt()
CVE-2025-39714 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmedia: usbtv: Lock resolution while streaming
CVE-2025-39719 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandiio: imu: bno055: fix OOB access of hw_xlate array
CVE-2025-39691 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandfs/buffer: fix use-after-free when call bh_read() helper
CVE-2025-38732 ↗2025-09-07cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandnetfilter: nf_reject: don't leak dst refcount for loopback packets
CVE-2025-39716 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandparisc: Revise __get_user() to probe user read access
CVE-2025-39675 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add null pointer check in mod_hdcp_hdcp1_create_session()
CVE-2025-39673 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandppp: fix race conditions in ppp_fill_forward_path
CVE-2025-39715 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandparisc: Revise gateway LWS calls to probe user read access
CVE-2025-39682 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandtls: fix handling of zero-length records on the rx_list
CVE-2025-39701 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandACPI: pfr_update: Fix the driver update version check
CVE-2025-38734 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet/smc: fix UAF on smcsk after smc_listen_out()
CVE-2025-39707 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities
CVE-2025-39706 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: Destroy KFD debugfs after destroy KFD wq
CVE-2025-39677 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandnet/sched: Fix backlog accounting in qdisc_dequeue_internal
CVE-2025-39705 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: fix a Null pointer dereference vulnerability
CVE-2025-39693 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Avoid a NULL pointer dereference
CVE-2025-39694 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bands390/sclp: Fix SCCB present check
CVE-2025-39687 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandiio: light: as73211: Ensure buffer holes are zeroed
CVE-2025-39721 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandcrypto: qat - flush misc workqueue during device shutdown
CVE-2025-39711 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandmedia: ivsc: Fix crash at shutdown due to missing mei_cldev_disable() calls
CVE-2025-39720 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix refcount leak causing resource not released
CVE-2025-39689 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandftrace: Also allocate and copy hash for reading of filter files
CVE-2025-39724 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandserial: 8250: fix panic due to PSLVERR
CVE-2025-39692 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandsmb: server: split ksmbd_rdma_stop_listening() out of ksmbd_rdma_destroy()
CVE-2025-39684 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: Fix use of uninitialized memory in do_insn_ioctl() and do_insnlist_ioctl()
CVE-2025-38735 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandgve: prevent ethtool ops after shutdown
CVE-2025-39718 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandvsock/virtio: Validate length in packet header before skb_put()
CVE-2025-39710 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandmedia: venus: Add a check for packet size after reading from shared memory
CVE-2025-39702 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandipv6: sr: Fix MAC comparison to be constant-time
CVE-2025-39686 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandcomedi: Make insn_rw_emulate_bits() do insn->n samples
CVE-2025-39685 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandcomedi: pcl726: Prevent invalid irq number
CVE-2025-39726 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bands390/ism: fix concurrency management in ism_cmd()
CVE-2025-39709 ↗2025-09-07azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandmedia: venus: protect against spurious interrupts during probe
CVE-2025-39697 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandNFS: Fix a race when updating an existing write
CVE-2025-39703 ↗2025-09-07azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet, hsr: reject HSR frame if skb can't hold tag
CVE-2025-38700 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandscsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated
CVE-2025-38713 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandhfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
CVE-2025-38701 ↗2025-09-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandext4: do not BUG when INLINE_DATA_FL lacks system.data xattr
CVE-2025-38706 ↗2025-09-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime()
CVE-2025-38704 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandrcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer access
CVE-2025-38725 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnet: usb: asix_devices: add phy_mask for ax88772 mdio bus
CVE-2025-38717 ↗2025-09-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: kcm: Fix race condition in kcm_unattach()
CVE-2025-38692 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandexfat: add cluster chain loop check for dir
CVE-2025-38722 ↗2025-09-06azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandhabanalabs: fix UAF in export_dmabuf()
CVE-2025-38703 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-banddrm/xe: Make dma-fences compliant with the safe access rules
CVE-2025-38728 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandsmb3: fix for slab out of bounds on mount to ksmbd
CVE-2025-38711 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandsmb/server: avoid deadlock when linking with ReplaceIfExists
CVE-2025-38721 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ctnetlink: fix refcount leak on table dump
CVE-2025-38712 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandhfsplus: don't use BUG_ON() in hfsplus_create_attributes_file()
CVE-2025-38679 ↗2025-09-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandmedia: venus: Fix OOB read due to missing payload bound check
CVE-2025-38687 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandcomedi: fix race between polling and detaching
CVE-2025-38702 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandfbdev: fix potential buffer overflow in do_register_framebuffer()
CVE-2025-38724 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandnfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
CVE-2025-38705 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/pm: fix null pointer access
CVE-2025-38699 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandscsi: bfa: Double-free fix
CVE-2025-38707 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandfs/ntfs3: Add sanity check for file name
CVE-2025-38716 ↗2025-09-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandhfs: fix general protection fault in hfs_find_init()
CVE-2025-38684 ↗2025-09-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandnet/sched: ets: use old 'nbands' while purging unused classes
CVE-2025-38697 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandjfs: upper bound check of tree index in dbAllocAG
CVE-2025-38714 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandhfsplus: fix slab-out-of-bounds in hfsplus_bnode_read()
CVE-2025-38730 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandio_uring/net: commit partial buffers on retry
CVE-2025-38715 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandhfs: fix slab-out-of-bounds in hfs_bnode_read()
CVE-2025-38708 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrbd: add missing kref_get in handle_write_conflicts
CVE-2025-38698 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandjfs: Regular file corruption check
CVE-2025-38695 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandscsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure
CVE-2025-38681 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandmm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd()
CVE-2025-38709 ↗2025-09-06azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bandloop: Avoid updating block size under exclusive owner
CVE-2025-38710 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandgfs2: Validate i_depth for exhash directories
CVE-2025-38680 ↗2025-09-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandmedia: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()
CVE-2025-38729 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandALSA: usb-audio: Validate UAC3 power domain descriptors, too
CVE-2025-38691 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandpNFS: Fix uninited ptr deref in block/scsi layout
CVE-2025-38696 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandMIPS: Don't crash in stack_top() for tasks without ABI or vDSO
CVE-2025-38685 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandfbdev: Fix vmalloc out-of-bounds write in fast_imageblit
CVE-2025-38723 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandLoongArch: BPF: Fix jump offset calculation in tailcall
CVE-2025-38718 ↗2025-09-06cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandsctp: linearize cloned gso packets in sctp_rcv
CVE-2025-38688 ↗2025-09-06azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandiommufd: Prevent ALIGN() overflow
CVE-2025-7039 ↗2025-09-05cbl2 glib 2.71.0-5 on CBL Mariner 2.0LowOut-of-bandGlib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file()
CVE-2025-9867 ↗2025-09-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-9867 Inappropriate implementation in Downloads
CVE-2025-9866 ↗2025-09-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-9866 Inappropriate implementation in Extensions
CVE-2025-9865 ↗2025-09-05Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-9865 Inappropriate implementation in Toolbar
CVE-2025-9864 ↗2025-09-05Microsoft Edge (Chromium-based)N/AOut-of-bandChromium: CVE-2025-9864 Use after free in V8
CVE-2025-53791 ↗2025-09-05Microsoft Edge (Chromium-based)ModerateOut-of-band0%Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2025-38678 ↗2025-09-04azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_tables: reject duplicate device on updates
CVE-2025-54914 ↗2025-09-04Azure NetworkingCriticalOut-of-band2%Azure Networking Elevation of Privilege Vulnerability
CVE-2025-55238 ↗2025-09-04Dynamics 365 FastTrack ImplementationCriticalOut-of-band1%Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
CVE-2025-55241 ↗2025-09-04Microsoft Entra IDCriticalOut-of-band2%Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-55242 ↗2025-09-04Xbox Gaming ServicesCriticalOut-of-band1%Xbox Certification Bug Copilot Djando Information Disclosure Vulnerability
CVE-2025-55244 ↗2025-09-04Azure Bot ServiceCriticalOut-of-band1%Azure Bot Service Elevation of Privilege Vulnerability