CYBERSECURITYTRACKER
TRACKING7,183 stories in this site build1,510 vulnerability news stories in this site build
Vulnerabilities

December 2025 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 1 vulnerability with exploitation detected in the wild this month. This defender-focused view covers 349 vulnerabilities across 349 returned patch records from 1 vendor. Filter the complete month, or browse the static page trail without JavaScript.

349all patch recordsClear filters15criticalShow these records1Microsoft exploitation detectedShow these records2Microsoft in the Known Exploited Vulnerabilities catalogShow these records83tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 1 of 2 · records 1 to 200 of 349

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2025-62221 ↗Windows 10 Version 1809 for 32-bit SystemsImportant3%Microsoft rates: Exploitation DetectedCISA KEVVulnCheckENISAKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-14174 ↗Microsoft Edge (Chromium-based)N/AOut-of-band22%Microsoft rating unavailableCISA KEVVulnCheckENISAChromium: CVE-2025-14174 Out of bounds memory access in ANGLE
CVE-2025-64663 ↗Azure Cognitive Service for LanguageCriticalOut-of-band1%Microsoft rates: N/ACustom Question Answering Elevation of Privilege Vulnerability
CVE-2025-64675 ↗Azure Cosmos DBCriticalOut-of-band1%Microsoft rates: N/AAzure Cosmos DB Spoofing Vulnerability
CVE-2025-64676 ↗Microsoft PurviewCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Purview eDiscovery Remote Code Execution Vulnerability
CVE-2025-64677 ↗Office Out-of-Box ExperienceCriticalOut-of-band1%Microsoft rates: N/AOffice Out-of-Box Experience Spoofing Vulnerability
CVE-2025-65037 ↗Azure Container AppsCriticalOut-of-band1%Microsoft rates: N/AAzure Container Apps Remote Code Execution Vulnerability
CVE-2025-65041 ↗Microsoft Partner CenterCriticalOut-of-band1%Microsoft rating unavailableMicrosoft Partner Center Elevation of Privilege Vulnerability
CVE-2025-62554 ↗Microsoft Office LTSC 2024 for 64-bit editionsCritical0%Microsoft rates: Exploitation Less LikelyKB5002819Microsoft Office Remote Code Execution Vulnerability
CVE-2025-62557 ↗Microsoft Office LTSC 2024 for 32-bit editionsCritical0%Microsoft rates: Exploitation Less LikelyKB5002819Microsoft Office Remote Code Execution Vulnerability
CVE-2025-68615 ↗cbl2 net-snmp 5.9.4-1 on CBL Mariner 2.0CriticalOut-of-bandNot availableMicrosoft rating unavailableNet-SNMP snmptrapd crash
CVE-2025-68206 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nft_ct: add seqadj extension for natted connections
CVE-2025-68193 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailabledrm/xe/guc: Add devm release action to safely tear down CT
CVE-2025-40251 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailabledevlink: rate: Unset parent pointer in devl_rate_nodes_destroy
CVE-2025-40244 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablehfsplus: fix KMSAN uninit-value issue in __hfsplus_ext_cache_extent()
CVE-2025-40242 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablegfs2: Fix unlikely race in gdlm_put_lock
CVE-2025-40262 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableInput: imx_sc_key - fix memory corruption on unload
CVE-2025-64669 ↗Windows Admin CenterImportant0%Microsoft rates: Exploitation Less LikelyWindows Admin Center Elevation of Privilege Vulnerability
CVE-2025-54100 ↗Windows 10 Version 1809 for 32-bit SystemsImportant2%Microsoft rates: Exploitation Less LikelyPublicly disclosedKB5071417KB5071501
and 13 moreKB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072033KB5074204KB5074353
PowerShell Remote Code Execution Vulnerability
CVE-2025-55233 ↗Windows 11 Version 25H2 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-59516 ↗Windows 10 Version 1809 for 32-bit SystemsImportant2%Microsoft rates: Exploitation More LikelyKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVE-2025-59517 ↗Windows 10 Version 1809 for 32-bit SystemsImportant2%Microsoft rates: Exploitation More LikelyKB5071413KB5071417
and 7 moreKB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVE-2025-62454 ↗Windows 11 Version 25H2 for ARM64-based SystemsImportant2%Microsoft rates: Exploitation More LikelyKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-62455 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5071501KB5071503
and 7 moreKB5071504KB5071505KB5071506KB5071507KB5071543KB5071544KB5071546
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2025-62456 ↗Windows 11 Version 25H2 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5071413KB5071417
and 4 moreKB5071542KB5071547KB5072014KB5072033
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
CVE-2025-62457 ↗Windows 11 Version 25H2 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2025-62458 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation More LikelyKB5071413KB5071417
and 8 moreKB5071501KB5071503KB5071505KB5071506KB5071543KB5071544KB5071546KB5071547
Win32k Elevation of Privilege Vulnerability
CVE-2025-62461 ↗Windows 11 Version 25H2 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62462 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62463 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 5 moreKB5071542KB5071546KB5071547KB5072014KB5072033
DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-62464 ↗Windows 11 Version 25H2 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62465 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 4 moreKB5071542KB5071547KB5072014KB5072033
DirectX Graphics Kernel Denial of Service Vulnerability
CVE-2025-62466 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 13 moreKB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Client-Side Caching Elevation of Privilege Vulnerability
CVE-2025-62467 ↗Windows 11 Version 25H2 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2025-62468 ↗Windows Server 2025 (Server Core installation)Important1%Microsoft rates: Exploitation More LikelyKB5071417KB5071542
and 2 moreKB5072014KB5072033
Windows Defender Firewall Service Information Disclosure Vulnerability
CVE-2025-62469 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation UnlikelyKB5072014KB5072033Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-62470 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation More LikelyKB5071413KB5071417
and 13 moreKB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-62472 ↗Windows 10 Version 1809 for 32-bit SystemsImportant2%Microsoft rates: Exploitation More LikelyKB5071413KB5071417
and 13 moreKB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2025-62473 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 13 moreKB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-62474 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 11 moreKB5071501KB5071503KB5071505KB5071506KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2025-62549 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 13 moreKB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-62550 ↗Azure Monitor AgentImportant1%Microsoft rates: Exploitation Less LikelyAzure Monitor Agent Remote Code Execution Vulnerability
CVE-2025-62552 ↗Microsoft Office 2019 for 32-bit editionsImportant1%Microsoft rates: Exploitation UnlikelyKB5002812Microsoft Access Remote Code Execution Vulnerability
CVE-2025-62553 ↗Microsoft Office 2019 for 32-bit editionsImportant1%Microsoft rates: Exploitation Less LikelyKB5002818KB5002820Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62555 ↗Microsoft SharePoint Enterprise Server 2016Important1%Microsoft rates: Exploitation Less LikelyKB5002802KB5002804
and 3 moreKB5002806KB5002816KB5002821
Microsoft Word Remote Code Execution Vulnerability
CVE-2025-62556 ↗Office Online ServerImportant1%Microsoft rates: Exploitation Less LikelyKB5002817KB5002820Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62558 ↗Microsoft SharePoint Enterprise Server 2016Important1%Microsoft rates: Exploitation Less LikelyKB5002802KB5002804
and 3 moreKB5002806KB5002816KB5002821
Microsoft Word Remote Code Execution Vulnerability
CVE-2025-62559 ↗Microsoft SharePoint Enterprise Server 2016Important1%Microsoft rates: Exploitation Less LikelyKB5002802KB5002804
and 3 moreKB5002806KB5002816KB5002821
Microsoft Word Remote Code Execution Vulnerability
CVE-2025-62560 ↗Office Online ServerImportant1%Microsoft rates: Exploitation UnlikelyKB5002817KB5002820Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62561 ↗Office Online ServerImportant1%Microsoft rates: Exploitation Less LikelyKB5002817KB5002818
and 1 moreKB5002820
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62562 ↗Microsoft SharePoint Enterprise Server 2016Important1%Microsoft rates: Exploitation UnlikelyKB5002802KB5002804
and 3 moreKB5002806KB5002816KB5002821
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2025-62563 ↗Office Online ServerImportant1%Microsoft rates: Exploitation Less LikelyKB5002817KB5002818
and 1 moreKB5002820
Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62564 ↗Office Online ServerImportant1%Microsoft rates: Exploitation Less LikelyKB5002817KB5002820Microsoft Excel Remote Code Execution Vulnerability
CVE-2025-62565 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 7 moreKB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows File Explorer Elevation of Privilege Vulnerability
CVE-2025-62567 ↗Windows 10 Version 1809 for x64-based SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5071413KB5071417
and 8 moreKB5071503KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Hyper-V Denial of Service Vulnerability
CVE-2025-62569 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5071542KB5072014
and 1 moreKB5072033
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2025-62570 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5072014KB5072033Windows Camera Frame Server Monitor Information Disclosure Vulnerability
CVE-2025-62571 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 13 moreKB5071501KB5071503KB5071504KB5071505KB5071506KB5071507KB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Installer Elevation of Privilege Vulnerability
CVE-2025-62572 ↗Windows Server 2025 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5072014KB5072033Application Information Service Elevation of Privilege Vulnerability
CVE-2025-62573 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 7 moreKB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2025-64658 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows File Explorer Elevation of Privilege Vulnerability
CVE-2025-64661 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 7 moreKB5071542KB5071543KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Shell Elevation of Privilege Vulnerability
CVE-2025-64666 ↗Microsoft Exchange Server 2019 Cumulative Update 15Important1%Microsoft rates: Exploitation Less LikelyKB5071873KB5071874
and 2 moreKB5071875KB5071876
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2025-64667 ↗Microsoft Exchange Server Subscription Edition RTMImportant1%Microsoft rates: Exploitation UnlikelyKB5071873KB5071874
and 2 moreKB5071875KB5071876
Microsoft Exchange Server Spoofing Vulnerability
CVE-2025-64670 ↗Windows Server 2022Important1%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 5 moreKB5071542KB5071546KB5071547KB5072014KB5072033
Windows DirectX Information Disclosure Vulnerability
CVE-2025-64671 ↗GitHub Copilot Plugin for JetBrains IDEsImportant0%Microsoft rates: Exploitation Less LikelyPublicly disclosedGitHub Copilot for Jetbrains Remote Code Execution Vulnerability
CVE-2025-64672 ↗Microsoft SharePoint Server Subscription EditionImportant1%Microsoft rates: Exploitation Less LikelyKB5002815Microsoft SharePoint Server Spoofing Vulnerability
CVE-2025-64673 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5071413KB5071417
and 6 moreKB5071542KB5071544KB5071546KB5071547KB5072014KB5072033
Windows Storage VSP Driver Elevation of Privilege Vulnerability
CVE-2025-64678 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5068779KB5068781
and 13 moreKB5068787KB5068791KB5068840KB5068861KB5068864KB5068865KB5068904KB5068905KB5068906KB5068907KB5068908KB5068909KB5068966
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-64679 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2025-64680 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5066586KB5066780
and 6 moreKB5066782KB5066791KB5066793KB5066835KB5066836KB5066837
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2023-54207 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableHID: uclogic: Correct devm device reference for hidinput input_dev name
CVE-2025-48637 ↗azl3 hyperv-daemons 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableIn multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-15284 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablearrayLimit bypass in bracket notation allows DoS via memory exhaustion
CVE-2025-34468 ↗azl3 libcap 2.69-10 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablelibcoap Stack-Based Buffer Overflow in Address Resolution DoS or Potential RCE
CVE-2025-68973 ↗azl3 gnupg2 2.4.7-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableIn GnuPG through 2.4.8, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write for crafted input. (For ExtendedLTS, 2.2.51 and later are fixed versions.)
CVE-2025-14180 ↗cbl2 php 8.1.33-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableNULL Pointer Dereference in PDO quoting
CVE-2025-13699 ↗azl3 mariadb 10.11.11-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableMariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability
CVE-2025-68380 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: ath11k: fix peer HE MCS assignment
CVE-2025-68346 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableALSA: dice: fix buffer overflow in detect_stream_formats()
CVE-2025-68367 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemacintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse
CVE-2025-68729 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: ath12k: Fix MSDU buffer types handling in RX error path
CVE-2025-68331 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableusb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer
CVE-2025-68476 ↗azl3 keda 2.14.1-7 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableKEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Credential
CVE-2025-68156 ↗azl3 coredns 1.11.4-11 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableExpr has Denial of Service via Unbounded Recursion in Builtin Functions
CVE-2025-68315 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablef2fs: fix to detect potential corrupted nid in free_nid_list
CVE-2025-68287 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableusb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call paths
CVE-2025-68290 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemost: usb: fix double free on late probe failure
CVE-2025-68301 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenet: atlantic: fix fragment overflow handling in RX path
CVE-2025-68304 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_core: lookup hci_conn on RX path on protocol side
CVE-2025-68311 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabletty: serial: ip22zilog: Use platform device for probing
CVE-2025-68284 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablelibceph: prevent potential out-of-bounds writes in handle_auth_session_key()
CVE-2025-68303 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableplatform/x86: intel: punit_ipc: fix memory corruption
CVE-2025-68307 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablecan: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs
CVE-2025-68297 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableceph: fix crash in process_v2_sparse_read() for encrypted directories
CVE-2025-68283 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablelibceph: replace BUG_ON with bounds check for map->max_osd
CVE-2025-68285 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablelibceph: fix potential use-after-free in have_mon_and_osd_map()
CVE-2025-2296 ↗azl3 edk2 20240524git3e722403cd16-10 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableUn-verified kernel bypass Secure Boot mechanism in direct boot mode
CVE-2025-68188 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabletcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check()
CVE-2025-68237 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemtdchar: fix integer overflow in read/write ioctls
CVE-2025-68254 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablestaging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing
CVE-2025-68256 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablestaging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser
CVE-2025-68227 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemptcp: Fix proto fallback detection with BPF
CVE-2025-68265 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenvme: fix admin request_queue lifetime
CVE-2025-68174 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableamd/amdkfd: enhance kfd process check in switch partition
CVE-2025-68261 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableext4: add i_data_sem protection in ext4_destroy_inline_data_nolock()
CVE-2025-68235 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenouveau/firmware: Add missing kfree() of nvkm_falcon_fw::boot
CVE-2025-68231 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemm/mempool: fix poisoning order>0 pages with HIGHMEM
CVE-2025-68266 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebfs: Reconstruct file type when loading from disk
CVE-2025-40362 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableceph: fix multifs mds auth caps issue
CVE-2025-68196 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Cache streams targeting link when performing LT automation
CVE-2025-68255 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablestaging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing
CVE-2025-68190 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked()
CVE-2025-68224 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablescsi: core: Fix a regression triggered by scsi_host_busy()
CVE-2025-14523 ↗azl3 libsoup 3.4.4-10 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableLibsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)
CVE-2025-58098 ↗azl3 httpd 2.4.65-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableApache HTTP Server: Server Side Includes adds query string to #exec cmd=...
CVE-2025-66471 ↗cbl2 python-urllib3 1.26.19-2 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableurllib3 Streaming API improperly handles highly compressed data
CVE-2025-66418 ↗cbl2 python-urllib3 1.26.19-2 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableurllib3 allows an unbounded number of links in the decompression chain
CVE-2025-40314 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantNot availableMicrosoft rating unavailableusb: cdns3: gadget: Use-after-free during failed initialization and exit of cdnsp gadget
CVE-2025-40312 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantNot availableMicrosoft rating unavailablejfs: Verify inode mode when loading from disk
CVE-2025-40319 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantNot availableMicrosoft rating unavailablebpf: Sync pending IRQ work before freeing ring buffer
CVE-2025-40272 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemm/secretmem: fix use-after-free race in fault handler
CVE-2025-59775 ↗cbl2 httpd 2.4.65-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableApache HTTP Server: NTLM Leakage on Windows through UNC SSRF
CVE-2025-40233 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableocfs2: clear extent cache after moving/defragmenting extents
CVE-2025-40223 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemost: usb: Fix use-after-free in hdm_disconnect
CVE-2025-40258 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemptcp: fix race condition in mptcp_schedule_work()
CVE-2025-40240 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablesctp: avoid NULL dereference when chunk data buffer is missing
CVE-2025-12385 ↗cbl2 qt5-qtbase 5.12.11-18 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableImproper validation of <img> tag size in Text component parser
CVE-2025-34297 ↗cbl2 tensorflow 2.11.1-2 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableKissFFT Integer Overflow Heap Buffer Overflow via kiss_fft_alloc
CVE-2025-66476 ↗azl3 vim 9.1.1616-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableVim for Windows Uncontrolled Search Path Element Remote Code Execution Vulnerability
CVE-2025-12819 ↗cbl2 pgbouncer 1.24.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableUntrusted search path in auth_query connection in PgBouncer
CVE-2025-66293 ↗cbl2 libpng 1.6.51-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableLIBPNG has an out-of-bounds read in png_image_read_composite
CVE-2025-61729 ↗azl3 golang 1.25.5-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableExcessive resource consumption when printing error string for host certificate validation in crypto/x509
CVE-2025-68251 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableerofs: avoid infinite loops due to corrupted subpage compact indexes
CVE-2025-67873 ↗azl3 rust 1.75.0-22 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableCapstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow
CVE-2025-68291 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose().
CVE-2025-69277 ↗azl3 libsodium 1.0.19-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.
CVE-2025-14178 ↗azl3 php 8.3.23-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHeap buffer overflow in array_merge()
CVE-2025-14177 ↗azl3 php 8.3.23-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableInformation Leak of Memory in getimagesize
CVE-2025-68972 ↗cbl2 gnupg2 2.4.0-3 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableIn GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.
CVE-2023-54061 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablex86: fix clear_user_rep_good() exception handling annotation
CVE-2025-68733 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmack: fix bug: unprivileged task can create labels
CVE-2025-68374 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemd: fix rcu protection in md_wakeup_thread
CVE-2025-68724 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id
CVE-2025-68376 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecoresight: ETR: Fix ETR buffer use-after-free issue
CVE-2025-68378 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Fix stackmap overflow check in __bpf_get_stackid()
CVE-2025-68364 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableocfs2: relax BUG() to ocfs2_error() in __ocfs2_move_extent()
CVE-2025-68379 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/rxe: Fix null deref on srq->rq.queue after resize failure
CVE-2025-68363 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Check skb->transport_header is set in bpf_skb_check_mtu
CVE-2025-68740 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableima: Handle error code returned by ima_filter_rule_match()
CVE-2023-54082 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableaf_unix: Fix null-ptr-deref in unix_stream_sendpage().
CVE-2025-68358 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: fix racy bitfield write in btrfs_clear_space_info_full()
CVE-2025-68372 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenbd: defer config put in recv_work
CVE-2025-68728 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablentfs3: fix uninit memory after failed mi_read in mi_format_new
CVE-2025-68725 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Do not let BPF test infra emit invalid GSO types to stack
CVE-2025-68365 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefs/ntfs3: Initialize allocated memory before use
CVE-2025-68742 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Fix invalid prog->stats access when update_effective_progs fails
CVE-2025-68356 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegfs2: Prevent recursive memory reclaim
CVE-2025-68746 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablespi: tegra210-quad: Fix timeout handling
CVE-2025-68344 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: wavefront: Fix integer overflow in sample size validation
CVE-2025-68347 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events
CVE-2025-68744 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Free special fields when update [lru_,]percpu_hash maps
CVE-2025-68745 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: qla2xxx: Clear cmds after chip reset
CVE-2025-68736 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelandlock: Fix handling of disconnected directories
CVE-2025-68366 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenbd: defer config unlock in nbd_genl_connect
CVE-2025-68357 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableiomap: allocate s_dio_done_wq for async reads as well
CVE-2023-54161 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableaf_unix: Fix null-ptr-deref in unix_stream_sendpage().
CVE-2025-68732 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegpu: host1x: Fix race in syncpt alloc/free
CVE-2025-68741 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: qla2xxx: Fix improper freeing of purex item
CVE-2025-68345 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_hda_read_acpi()
CVE-2025-68362 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: rtl818x: rtl8187: Fix potential buffer underflow in rtl8187_rx_cb()
CVE-2025-68354 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableregulator: core: Protect regulator_supply_alias_list with regulator_list_mutex
CVE-2025-68349 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid
CVE-2025-68371 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: smartpqi: Fix device resources accessed after device removal
CVE-2025-68343 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecan: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing header
CVE-2025-68340 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableteam: Move team device type change at the end of team_port_add
CVE-2025-68342 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecan: gs_usb: gs_usb_receive_bulk_callback(): check actual_length before accessing data
CVE-2025-68338 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: dsa: microchip: Don't free uninitialized ksz_irq
CVE-2025-68339 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableatm/fore200e: Fix possible data race in fore200e_open()
CVE-2025-68334 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableplatform/x86/amd/pmc: Add support for Van Gogh SoC
CVE-2025-68328 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefirmware: stratix10-svc: fix bug in saving controller data
CVE-2025-68330 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableiio: accel: bmc150: Fix irq assumption regression
CVE-2025-68336 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelocking/spinlock/debug: Fix data-race in do_raw_write_lock
CVE-2025-68333 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesched_ext: Fix possible deadlock in the deferred_irq_workfn()
CVE-2025-68327 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: renesas_usbhs: Fix synchronous external abort on unbind
CVE-2025-68335 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecomedi: pcl818: fix null-ptr-deref in pcl818_ai_cancel()
CVE-2025-68332 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecomedi: c6xdigio: Fix invalid PNP driver unregistration
CVE-2025-68337 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablejbd2: avoid bug_on in jbd2_journal_get_create_access() when file system corrupted
CVE-2025-68114 ↗azl3 rust 1.75.0-22 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableCapstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow
CVE-2025-68161 ↗azl3 javapackages-bootstrap 1.14.0-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableApache Log4j Core: Missing TLS hostname verification in Socket appender
CVE-2025-59529 ↗cbl2 avahi 0.8-4 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesimple protocol server ignores accepts unlimited connections and logs failures without limit
CVE-2025-68384 ↗cbl2 rubygem-elasticsearch 8.3.0-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableElasticsearch Allocation of Resources Without Limits or Throttling
CVE-2025-68390 ↗cbl2 rubygem-elasticsearch 8.3.0-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableElasticsearch Allocation of Resources Without Limits or Throttling
CVE-2025-68324 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: imm: Fix use-after-free bug caused by unfinished delayed work
CVE-2025-68146 ↗azl3 python-filelock 3.14.0-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefilelock has TOCTOU race condition that allows symlink attacks during lock file creation
CVE-2025-68302 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: sxgbe: fix potential NULL dereference in sxgbe_rx()
CVE-2025-68289 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: gadget: f_eem: Fix memory leak in eem_unwrap
CVE-2025-68296 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup
CVE-2025-68308 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecan: kvaser_usb: leaf: Fix potential infinite loop in command parsers
CVE-2025-68318 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableclk: thead: th1520-ap: set all AXI clocks to CLK_IS_CRITICAL

Glossary