CYBERSECURITYTRACKER
TRACKING3,612 stories653 vuln stories
Patch Day month

November 2025 vulnerabilities

A server-rendered hunting trail for November 2025: 184 returned patch records across 1 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.

184all patches
14critical
1exploitation detected
3in CISA KEV
81tracked here
Microsoft 184

Page 1 of 1 · records 1–184 of 184

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-40213 ↗2026-06-10azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete
CVE-2025-12638 ↗2025-12-03azl3 keras 3.3.3-5 on Azure Linux 3.0ImportantOut-of-bandPath Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_file()
CVE-2025-66221 ↗2025-12-03azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandWerkzeug safe_join() allows Windows special device names
CVE-2025-61915 ↗2025-11-30azl3 cups 2.4.13-1 on Azure Linux 3.0ModerateOut-of-bandOpenPrinting CUPS vulnerable to stack based out-of-bound write
CVE-2025-58436 ↗2025-11-30azl3 cups 2.4.13-1 on Azure Linux 3.0ModerateOut-of-bandOpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack
CVE-2025-66031 ↗2025-11-29azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandnode-forge ASN.1 Unbounded Recursion
CVE-2025-66030 ↗2025-11-29cbl2 reaper 3.1.1-19 on CBL Mariner 2.0ModerateOut-of-bandnode-forge ASN.1 OID Integer Truncation
CVE-2025-12816 ↗2025-11-29cbl2 reaper 3.1.1-19 on CBL Mariner 2.0ImportantOut-of-bandCVE-2025-12816
CVE-2025-13601 ↗2025-11-29cbl2 glib 2.71.0-7 on CBL Mariner 2.0ImportantOut-of-bandGlib: integer overflow in in g_escape_uri_string()
CVE-2025-64713 ↗2025-11-29cbl2 fluent-bit 3.0.6-4 on CBL Mariner 2.0ModerateOut-of-bandWebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode
CVE-2025-64704 ↗2025-11-29azl3 fluent-bit 3.1.9-6 on Azure Linux 3.0ModerateOut-of-bandWebAssembly Micro Runtime vulnerable to a segmentation fault in v128.store instruction
CVE-2025-12977 ↗2025-11-29azl3 fluent-bit 3.1.9-6 on Azure Linux 3.0ImportantOut-of-bandCVE-2025-12977
CVE-2025-12969 ↗2025-11-29cbl2 fluent-bit 3.0.6-4 on CBL Mariner 2.0ModerateOut-of-bandCVE-2025-12969
CVE-2025-12970 ↗2025-11-29azl3 fluent-bit 3.1.10-2 on Azure Linux 3.0ImportantOut-of-bandCVE-2025-12970
CVE-2025-2486 ↗2025-11-29cbl2 edk2 20230301gitf80f052277c8-43 on CBL Mariner 2.0LowOut-of-bandUEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu
CVE-2025-66382 ↗2025-11-29azl3 expat 2.6.4-2 on Azure Linux 3.0LowOut-of-bandIn libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
CVE-2025-64506 ↗2025-11-27azl3 libpng 1.6.40-1 on Azure Linux 3.0ModerateOut-of-bandLIBPNG is vulnerable to a heap buffer over-read in `png_write_image_8bit` with grayscale+alpha or RGB/RGBA images
CVE-2025-64720 ↗2025-11-27Windows 10 Version 1809 for 32-bit SystemsImportantOut-of-band0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication
CVE-2025-65018 ↗2025-11-27Windows 10 Version 1809 for 32-bit SystemsImportantOut-of-band0%KB5082052KB5082060
and 9 moreKB5082063KB5082123KB5082126KB5082127KB5082142KB5082198KB5082200KB5083768KB5083769
LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`
CVE-2025-64505 ↗2025-11-26cbl2 qt5-qtbase 5.12.11-18 on CBL Mariner 2.0ModerateOut-of-bandLIBPNG is vulnerable to a heap buffer overflow in `png_do_quantize` via malformed palette index
CVE-2025-11932 ↗2025-11-25cbl2 mariadb 10.6.21-1 on CBL Mariner 2.0LowOut-of-bandTiming Side-Channel in PSK Binder Verification
CVE-2025-11933 ↗2025-11-25azl3 mariadb 10.11.11-1 on Azure Linux 3.0LowOut-of-bandDoS Vulnerability in wolfSSL TLS 1.3 CKS Extension
CVE-2025-12889 ↗2025-11-25azl3 mariadb 10.11.11-1 on Azure Linux 3.0LowOut-of-bandTLS 1.2 Client Can Downgrade Digest Used
CVE-2025-11934 ↗2025-11-25azl3 mariadb 10.11.11-1 on Azure Linux 3.0LowOut-of-bandImproper Validation of Signature Algorithm Used in TLS 1.3 CertificateVerify
CVE-2025-11931 ↗2025-11-25cbl2 mariadb 10.6.21-1 on CBL Mariner 2.0LowOut-of-bandInteger Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt
CVE-2025-11936 ↗2025-11-25azl3 mariadb 10.11.11-1 on Azure Linux 3.0ModerateOut-of-bandPotential DoS Vulnerability through Multiple KeyShareEntry with Same Group in TLS 1.3 ClientHello
CVE-2025-12888 ↗2025-11-25cbl2 mariadb 10.6.21-1 on CBL Mariner 2.0LowOut-of-bandConstant Time Issue with Xtensa-based ESP32 and X22519
CVE-2025-11935 ↗2025-11-25azl3 mariadb 10.11.11-1 on Azure Linux 3.0ModerateOut-of-bandForward Secrecy Violation in WolfSSL TLS 1.3
CVE-2025-40210 ↗2025-11-22azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandRevert "NFSD: Remove the cap on number of operations per NFSv4 COMPOUND"
CVE-2025-40211 ↗2025-11-22azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandACPI: video: Fix use-after-free in acpi_video_switch_brightness()
CVE-2025-13227 ↗2025-11-21azl3 nodejs 20.14.0-9 on Azure Linux 3.0ImportantOut-of-bandType Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-13193 ↗2025-11-21azl3 libvirt 10.0.0-5 on Azure Linux 3.0ModerateOut-of-bandLibvirt: information disclosure via world-readable vm snapshots
CVE-2025-13226 ↗2025-11-21cbl2 nodejs18 18.20.3-9 on CBL Mariner 2.0ImportantOut-of-bandType Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-13230 ↗2025-11-21cbl2 nodejs18 18.20.3-9 on CBL Mariner 2.0ImportantOut-of-bandType Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-11230 ↗2025-11-21cbl2 haproxy 2.4.24-1 on CBL Mariner 2.0ModerateOut-of-bandDenial of service vulnerability in HAProxy mjson library
CVE-2025-54770 ↗2025-11-21cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: use-after-free in net_set_vlan
CVE-2025-54771 ↗2025-11-21cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: use-after-free in grub_file_close()
CVE-2025-61664 ↗2025-11-21cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: missing unregister call for normal_exit command may lead to use-after-free
CVE-2025-61661 ↗2025-11-21cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: grub2: out-of-bounds write via malicious usb device
CVE-2025-61663 ↗2025-11-21cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: missing unregister call for normal commands may lead to use-after-free
CVE-2025-61662 ↗2025-11-21cbl2 grub2 2.06-15 on CBL Mariner 2.0ModerateOut-of-bandGrub2: missing unregister call for gettext command may lead to use-after-free
CVE-2025-64324 ↗2025-11-20azl3 kubevirt 1.5.3-2 on Azure Linux 3.0ImportantOut-of-bandKubeVirt Vulnerable to Arbitrary Host File Read and Write
CVE-2025-49752 ↗2025-11-20Azure Bastion DeveloperCriticalOut-of-band1%Azure Bastion Elevation of Privilege Vulnerability
CVE-2025-59245 ↗2025-11-20Microsoft SharePoint OnlineCriticalOut-of-band1%Microsoft SharePoint Online Elevation of Privilege Vulnerability
CVE-2025-62207 ↗2025-11-20Azure Monitor Control ServiceCriticalOut-of-band1%Azure Monitor Elevation of Privilege Vulnerability
CVE-2025-62459 ↗2025-11-20Microsoft 365 Defender PortalCriticalOut-of-band0%Microsoft Defender Portal Spoofing Vulnerability
CVE-2025-64655 ↗2025-11-20Dynamics OmniChannel SDK Storage ContainersCriticalOut-of-band0%More likelyDynamics OmniChannel SDK Storage Containers Elevation of Privilege Vulnerability
CVE-2025-64656 ↗2025-11-20Azure App GatewayCriticalOut-of-band1%Azure Application Gateway Elevation of Privilege Vulnerability
CVE-2025-64657 ↗2025-11-20Azure App GatewayCriticalOut-of-band1%Azure Application Gateway Elevation of Privilege Vulnerability
CVE-2025-64660 ↗2025-11-20Visual Studio CodeImportantOut-of-band1%GitHub Copilot and Visual Studio Code Remote Code Execution Vulnerability
CVE-2025-13120 ↗2025-11-19cbl2 rust 1.72.0-11 on CBL Mariner 2.0ModerateOut-of-bandmruby array.c sort_cmp use after free
CVE-2025-10158 ↗2025-11-19azl3 rsync 3.4.1-1 on Azure Linux 3.0ModerateOut-of-bandRsync: Out of bounds array access via negative index
CVE-2025-13224 ↗2025-11-18Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13224 Type Confusion in V8
CVE-2025-13223 ↗2025-11-18Microsoft Edge (Chromium-based)N/AOut-of-band5%CISA KEVVulnCheckENISAChromium: CVE-2025-13223 Type Confusion in V8
CVE-2025-47913 ↗2025-11-17cbl2 moby-compose 2.17.3-11 on CBL Mariner 2.0ImportantOut-of-bandPotential denial of service in golang.org/x/crypto/ssh/agent
CVE-2025-12748 ↗2025-11-15azl3 libvirt 10.0.0-6 on Azure Linux 3.0ModerateOut-of-bandLibvirt: denial of service in xml parsing
CVE-2025-12817 ↗2025-11-14cbl2 postgresql 14.19-1 on CBL Mariner 2.0LowOut-of-bandPostgreSQL CREATE STATISTICS does not check for schema CREATE privilege
CVE-2025-12818 ↗2025-11-14azl3 rust 1.90.0-3 on Azure Linux 3.0ModerateOut-of-bandPostgreSQL libpq undersizes allocations, via integer wraparound
CVE-2025-40202 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandipmi: Rework user message limit handling
CVE-2025-40204 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandsctp: Fix MAC comparison to be constant-time
CVE-2025-40193 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandxtensa: simdisk: add input size check in proc_write_simdisk
CVE-2025-40192 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandRevert "ipmi: fix msg stack when IPMI is disconnected"
CVE-2025-40197 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmedia: mc: Clear minor number before put device
CVE-2025-40206 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_objref: validate objref and objrefmap expressions
CVE-2025-40205 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandbtrfs: avoid potential out-of-bounds in btrfs_encode_fh()
CVE-2025-40194 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandcpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request()
CVE-2025-40190 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandext4: guard against EA inode refcount underflow in xattr update
CVE-2025-40201 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandkernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths
CVE-2025-40178 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandpid: Add a judgment for ns null in pid_nr_ns
CVE-2025-40188 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandpwm: berlin: Fix wrong register in suspend/resume
CVE-2025-40187 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce()
CVE-2025-40195 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmount: handle NULL values in mnt_ns_release()
CVE-2025-40200 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandSquashfs: reject negative file sizes in squashfs_read_inode()
CVE-2025-40207 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandmedia: v4l2-subdev: Fix alloc failure check in v4l2_subdev_call_state_try()
CVE-2025-40198 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandext4: avoid potential buffer over-read in parse_apply_sb_mount_options()
CVE-2025-40180 ↗2025-11-14azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandmailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox cleanup loop
CVE-2025-40179 ↗2025-11-14azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandext4: verify orphan file size is not too big
CVE-2024-47866 ↗2025-11-14azl3 ceph 18.2.2-11 on Azure Linux 3.0ImportantOut-of-bandRGW DoS attack with empty HTTP header in S3 object copy
CVE-2011-10034 ↗2025-11-14azl3 autogen 5.18.16-9 on Azure Linux 3.0ModerateOut-of-bandIRAI AUTOMGEN <= 8.0.0.7 Use-After-Free Remote DoS
CVE-2025-13042 ↗2025-11-13Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-13042 Inappropriate implementation in V8
CVE-2025-62689 ↗2025-11-13azl3 libmicrohttpd 0.9.77-3 on Azure Linux 3.0ImportantOut-of-bandNULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
CVE-2025-59777 ↗2025-11-13azl3 libmicrohttpd 0.9.77-3 on Azure Linux 3.0ImportantOut-of-bandNULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
CVE-2025-40176 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandtls: wait for pending async decryptions if tls_strp_msg_hold fails
CVE-2025-40158 ↗2025-11-13azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandipv6: use RCU in ip6_output()
CVE-2025-40170 ↗2025-11-13azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandnet: use dst_dev_rcu() in sk_setup_caps()
CVE-2025-40173 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandnet/ip6_tunnel: Prevent perpetual tunnel growth
CVE-2025-40165 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandmedia: nxp: imx8-isi: m2m: Fix streaming cleanup on release
CVE-2025-40168 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandsmc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match().
CVE-2025-40164 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandusbnet: Fix using smp_processor_id() in preemptible code warnings
CVE-2025-40172 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandaccel/qaic: Treat remaining == 0 as error in find_and_map_user_pages()
CVE-2025-40146 ↗2025-11-13azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandblk-mq: fix potential deadlock while nr_requests grown
CVE-2025-40149 ↗2025-11-13azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandtls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock().
CVE-2025-40139 ↗2025-11-13azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandsmc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
CVE-2025-40135 ↗2025-11-13azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandipv6: use RCU in ip6_xmit()
CVE-2025-40167 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandext4: detect invalid INLINE_DATA + EXTENTS flag combination
CVE-2025-40136 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-bandcrypto: hisilicon/qm - request reserved interrupt for virtual function
CVE-2025-60876 ↗2025-11-13azl3 busybox 1.36.1-19 on Azure Linux 3.0ImportantOut-of-bandBusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
CVE-2025-40111 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/vmwgfx: Fix Use-after-free in validation
CVE-2025-40110 ↗2025-11-13azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/vmwgfx: Fix a null-ptr access in the cursor snooper
CVE-2025-60710 ↗2025-11-11Windows Server 2025 (Server Core installation)Important5%CISA KEVVulnCheckENISAKB5072014KB5072033Host Process for Windows Tasks Elevation of Privilege Vulnerability
CVE-2025-12875 ↗2025-11-11azl3 nghttp2 1.61.0-2 on Azure Linux 3.0Moderatemruby array.c ary_fill_exec out-of-bounds write
CVE-2025-12863 ↗2025-11-11cbl2 libxml2 2.10.4-9 on CBL Mariner 2.0ImportantLibxml2: namespace use-after-free in xmlsettreedoc() function of libxml2
CVE-2025-60753 ↗2025-11-11azl3 libarchive 3.7.7-3 on Azure Linux 3.0ModerateAn issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).
CVE-2025-30398 ↗2025-11-11Nuance PowerScribe 360 version 4.0.5Critical1%Nuance PowerScribe 360 Information Disclosure Vulnerability
CVE-2025-47179 ↗2025-11-11Microsoft Configuration Manager 2403Important0%Configuration Manager Elevation of Privilege Vulnerability
CVE-2025-59240 ↗2025-11-11Microsoft Office LTSC 2021 for 32-bit editionsImportant1%KB5002811Microsoft Excel Information Disclosure Vulnerability
CVE-2025-59499 ↗2025-11-11Microsoft SQL Server 2017 for x64-based Systems (GDR)Important1%KB5068400KB5068401
and 6 moreKB5068402KB5068403KB5068404KB5068405KB5068406KB5068407
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-59504 ↗2025-11-11Azure MonitorImportant0%Azure Monitor Agent Remote Code Execution Vulnerability
CVE-2025-59505 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 9 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068905KB5068907KB5068966
Windows Smart Card Reader Elevation of Privilege Vulnerability
CVE-2025-59506 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 9 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068905KB5068907KB5068966
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-59507 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 7 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068966
Windows Speech Runtime Elevation of Privilege Vulnerability
CVE-2025-59508 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 7 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068966
Windows Speech Recognition Elevation of Privilege Vulnerability
CVE-2025-59509 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 6 moreKB5068787KB5068791KB5068840KB5068861KB5068865KB5068966
Windows Speech Recognition Information Disclosure Vulnerability
CVE-2025-59510 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 8 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068905KB5068966
Windows Routing and Remote Access Service (RRAS) Denial of Service Vulnerability
CVE-2025-59511 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 6 moreKB5068787KB5068791KB5068840KB5068861KB5068865KB5068966
Windows WLAN Service Elevation of Privilege Vulnerability
CVE-2025-59512 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant3%More likelyKB5068779KB5068781
and 9 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068905KB5068907KB5068966
Customer Experience Improvement Program (CEIP) Elevation of Privilege Vulnerability
CVE-2025-59513 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 11 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068906KB5068908KB5068909KB5068966
Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability
CVE-2025-59514 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
CVE-2025-59515 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 4 moreKB5068791KB5068861KB5068865KB5068966
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability
CVE-2025-60703 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Remote Desktop Services Elevation of Privilege Vulnerability
CVE-2025-60704 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Kerberos Elevation of Privilege Vulnerability
CVE-2025-60705 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Client-Side Caching Elevation of Privilege Vulnerability
CVE-2025-60706 ↗2025-11-11Windows 10 Version 1809 for x64-based SystemsImportant0%KB5068779KB5068781
and 7 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068966
Windows Hyper-V Information Disclosure Vulnerability
CVE-2025-60707 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 6 moreKB5068787KB5068791KB5068840KB5068861KB5068865KB5068966
Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability
CVE-2025-60708 ↗2025-11-11Windows 10 Version 1809 for x64-based SystemsImportant0%KB5068779KB5068781
and 7 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068966
Storvsp.sys Driver Denial of Service Vulnerability
CVE-2025-60709 ↗2025-11-11Windows 11 Version 25H2 for ARM64-based SystemsImportant1%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-60713 ↗2025-11-11Windows Server 2019Important0%KB5068779KB5068787
and 5 moreKB5068791KB5068840KB5068861KB5068864KB5068966
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
CVE-2025-60714 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 11 moreKB5068787KB5068791KB5068840KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909
Windows OLE Remote Code Execution Vulnerability
CVE-2025-60715 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-60716 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5068779KB5068781
and 6 moreKB5068787KB5068791KB5068840KB5068861KB5068865KB5068966
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-60717 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 4 moreKB5068791KB5068861KB5068865KB5068966
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability
CVE-2025-60718 ↗2025-11-11Windows 11 Version 24H2 for ARM64-based SystemsImportant0%KB5068861KB5068966Windows Administrator Protection Elevation of Privilege Vulnerability
CVE-2025-60719 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-60720 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability
CVE-2025-60721 ↗2025-11-11Windows 11 Version 25H2 for x64-based SystemsImportant0%KB5068861KB5068966Windows Administrator Protection Elevation of Privilege Vulnerability
CVE-2025-60722 ↗2025-11-11OneDrive for AndroidImportant1%Microsoft OneDrive for Android Elevation of Privilege Vulnerability
CVE-2025-60723 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 6 moreKB5068787KB5068791KB5068840KB5068861KB5068865KB5068966
DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-60724 ↗2025-11-11Microsoft Office LTSC for Mac 2021Critical6%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
GDI+ Remote Code Execution Vulnerability
CVE-2025-60726 ↗2025-11-11Office Online ServerImportant1%KB5002801KB5002810
and 1 moreKB5002811
Microsoft Excel Information Disclosure Vulnerability
CVE-2025-60727 ↗2025-11-11Office Online ServerImportant1%KB5002801KB5002810
and 1 moreKB5002811
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-60728 ↗2025-11-11Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant1%Microsoft Excel Information Disclosure Vulnerability
CVE-2025-62199 ↗2025-11-11Microsoft Office 2016 (32-bit edition)Critical1%KB5002809Microsoft Office Remote Code Execution Vulnerability
CVE-2025-62200 ↗2025-11-11Office Online ServerImportant0%KB5002801KB5002811Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62201 ↗2025-11-11Office Online ServerImportant0%KB5002801KB5002811Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62202 ↗2025-11-11Office Online ServerImportant1%KB5002801KB5002810
and 1 moreKB5002811
Microsoft Excel Information Disclosure Vulnerability
CVE-2025-62203 ↗2025-11-11Office Online ServerImportant0%KB5002801KB5002811Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62204 ↗2025-11-11Microsoft SharePoint Enterprise Server 2016Important2%KB5002800KB5002803
and 1 moreKB5002805
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2025-62205 ↗2025-11-11Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Office Remote Code Execution Vulnerability
CVE-2025-62206 ↗2025-11-11Microsoft Dynamics 365 (on-premises) version 9.1Important1%KB5067331Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2025-62208 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows License Manager Information Disclosure Vulnerability
CVE-2025-62209 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows License Manager Information Disclosure Vulnerability
CVE-2025-62210 ↗2025-11-11Dynamics 365 Field Service (online)Important1%Dynamics 365 Field Service (online) Spoofing Vulnerability
CVE-2025-62211 ↗2025-11-11Dynamics 365 Field Service (online)Important1%Dynamics 365 Field Service (online) Spoofing Vulnerability
CVE-2025-62213 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant2%More likelyKB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-62214 ↗2025-11-11Microsoft Visual Studio 2022 version 17.14Critical1%Visual Studio Remote Code Execution Vulnerability
CVE-2025-62215 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant6%Exploitation detectedCISA KEVVulnCheckENISAKB5068779KB5068781
and 6 moreKB5068787KB5068791KB5068840KB5068861KB5068865KB5068966
Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-62216 ↗2025-11-11Microsoft 365 Apps for Enterprise for 32-bit SystemsImportant0%Microsoft Office Remote Code Execution Vulnerability
CVE-2025-62217 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%More likelyKB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-62218 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068781KB5068791
and 4 moreKB5068861KB5068864KB5068865KB5068966
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability
CVE-2025-62219 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant0%KB5068781KB5068791
and 4 moreKB5068861KB5068864KB5068865KB5068966
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability
CVE-2025-62220 ↗2025-11-11Windows Subsystem for Linux GUIImportant1%Windows Subsystem for Linux GUI Remote Code Execution Vulnerability
CVE-2025-62222 ↗2025-11-11Microsoft Visual Studio Code CoPilot Chat ExtensionImportant1%Agentic AI and Visual Studio Code Remote Code Execution Vulnerability
CVE-2025-62449 ↗2025-11-11Microsoft Visual Studio Code CoPilot Chat ExtensionImportant0%Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability
CVE-2025-62452 ↗2025-11-11Windows 10 Version 1809 for 32-bit SystemsImportant1%KB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-62453 ↗2025-11-11Visual Studio CodeImportant0%GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
CVE-2025-40109 ↗2025-11-10azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandcrypto: rng - Ensure set_ent is always present
CVE-2025-12729 ↗2025-11-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12729 Inappropriate implementation in Omnibox
CVE-2025-12728 ↗2025-11-10Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12728 Inappropriate implementation in Omnibox
CVE-2025-52881 ↗2025-11-09cbl2 moby-runc 1.1.9-9 on CBL Mariner 2.0ImportantOut-of-bandrunc: LSM labels can be bypassed with malicious config using dummy procfs files
CVE-2025-52565 ↗2025-11-09cbl2 kubernetes 1.28.4-19 on CBL Mariner 2.0ImportantOut-of-bandcontainer escape due to /dev/console mount and related races
CVE-2025-31133 ↗2025-11-09cbl2 moby-runc 1.1.9-9 on CBL Mariner 2.0ImportantOut-of-bandrunc container escape via "masked path" abuse due to mount race conditions
CVE-2025-64437 ↗2025-11-09cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0ModerateOut-of-bandKubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
CVE-2025-64435 ↗2025-11-09azl3 kubevirt 1.5.0-5 on Azure Linux 3.0ModerateOut-of-bandKubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation
CVE-2025-64433 ↗2025-11-09cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0ModerateOut-of-bandKubeVirt Arbitrary Container File Read
CVE-2025-64434 ↗2025-11-09cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0ModerateOut-of-bandKubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing
CVE-2025-64432 ↗2025-11-09cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0ModerateOut-of-bandKubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
CVE-2025-64436 ↗2025-11-09cbl2 kubevirt 0.59.0-30 on CBL Mariner 2.0ModerateOut-of-bandKubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
CVE-2024-25621 ↗2025-11-08cbl2 moby-containerd 1.6.26-12 on CBL Mariner 2.0ImportantOut-of-bandcontainerd affected by a local privilege escalation via wide permissions on CRI directory
CVE-2025-10966 ↗2025-11-08azl3 cmake 3.30.3-10 on Azure Linux 3.0ModerateOut-of-bandmissing SFTP host verification with wolfSSH
CVE-2025-64329 ↗2025-11-08azl3 containerd2 2.0.0-14 on Azure Linux 3.0ModerateOut-of-bandcontainerd CRI server: Host memory exhaustion through Attach goroutine leak
CVE-2025-12727 ↗2025-11-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12727 Inappropriate implementation in V8
CVE-2025-12726 ↗2025-11-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12726 Inappropriate implementation in Views.
CVE-2025-12725 ↗2025-11-06Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2025-12725 Out of bounds write in WebGPU
CVE-2025-40107 ↗2025-11-04azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ModerateOut-of-bandcan: hi311x: fix null pointer dereference when resuming from sleep before interface was enabled