Total CVEs

137

Critical

17

Important

118

Exploited

1

Publicly Disclosed

1

All CVEs this month 137

CVE Title Severity CVSS Product Exploited Disclosed Diffed
CVE-2025-26636 Windows Kernel Information Disclosure Vulnerability Important 5.5 Windows Kernel - - -
CVE-2025-33054 Remote Desktop Spoofing Vulnerability Important 8.1 Remote Desktop Client - - -
CVE-2025-47159 Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability Important 7.8 Windows Virtualization-Based Security (VBS) Enclave - - -
CVE-2025-21195 Azure Service Fabric Runtime Elevation of Privilege Vulnerability Important 6 Service Fabric - - -
CVE-2025-47971 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability Important 7.8 Virtual Hard Disk (VHDX) - - -
CVE-2025-47972 Windows Input Method Editor (IME) Elevation of Privilege Vulnerability Important 8 Microsoft Input Method Editor (IME) - - -
CVE-2025-47976 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability Important 7.8 Windows SSDP Service - - -
CVE-2025-47984 Windows GDI Information Disclosure Vulnerability Important 7.5 Windows GDI - - -
CVE-2025-47985 Windows Event Tracing Elevation of Privilege Vulnerability Important 7.8 Windows Event Tracing - - -
CVE-2025-47986 Universal Print Management Service Elevation of Privilege Vulnerability Important 8.8 Universal Print Management Service - - -
CVE-2025-47987 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability Important 7.8 Windows Cred SSProvider Protocol - - -
CVE-2025-48824 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49657 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49658 Windows Transport Driver Interface (TDI) Translation Driver Information Disclosure Vulnerability Important 5.5 Windows TDX.sys - - -
CVE-2025-49661 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7.8 Windows Ancillary Function Driver for WinSock - - -
CVE-2025-49670 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 6.5 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49671 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Important 6.5 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49672 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49674 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49676 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49677 Microsoft Brokering File System Elevation of Privilege Vulnerability Important 7 Microsoft Brokering File System - - -
CVE-2025-49686 Windows TCP/IP Driver Elevation of Privilege Vulnerability Important 7.8 Windows TCP/IP - - -
CVE-2025-49687 Windows Input Method Editor (IME) Elevation of Privilege Vulnerability Important 8.8 Microsoft Input Method Editor (IME) - - -
CVE-2025-49688 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49689 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability Important 7.8 Virtual Hard Disk (VHDX) - - -
CVE-2025-49690 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability Important 7.4 Capability Access Management Service (camsvc) - - -
CVE-2025-49691 Windows Miracast Wireless Display Remote Code Execution Vulnerability Important 8 Windows Media - - -
CVE-2025-49694 Microsoft Brokering File System Elevation of Privilege Vulnerability Important 7.8 Microsoft Brokering File System - - -
CVE-2025-47991 Windows Input Method Editor (IME) Elevation of Privilege Vulnerability Important 7.8 Microsoft Input Method Editor (IME) - - -
CVE-2025-47993 Microsoft PC Manager Elevation of Privilege Vulnerability Important 7.8 Microsoft PC Manager - - -
CVE-2025-47994 Microsoft Office Elevation of Privilege Vulnerability Important 8.6 Microsoft Office - - -
CVE-2025-48812 Microsoft Excel Information Disclosure Vulnerability Important 5.5 Microsoft Office Excel - - -
CVE-2025-49711 Microsoft Excel Remote Code Execution Vulnerability Important 7.8 Microsoft Office Excel - - -
CVE-2025-49716 Windows Netlogon Denial of Service Vulnerability Important 7.5 Windows Netlogon - - -
CVE-2025-49717 Microsoft SQL Server Remote Code Execution Vulnerability Important 8.5 SQL Server - - -
CVE-2025-49719 Microsoft SQL Server Information Disclosure Vulnerability Important 7.5 SQL Server - Yes -
CVE-2025-49721 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability Important 7.8 Windows Fast FAT Driver - - -
CVE-2025-49723 Windows StateRepository API Server file Tampering Vulnerability Important 8.8 Windows StateRepository API - - -
CVE-2025-49726 Windows Notification Elevation of Privilege Vulnerability Important 7.8 Windows Notification - - -
CVE-2025-49731 Microsoft Teams Elevation of Privilege Vulnerability Important 3.1 Microsoft Teams - - -
CVE-2025-49735 Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability Critical 8.1 Windows KDC Proxy Service (KPSSVC) - - -
CVE-2025-47178 Microsoft Configuration Manager Remote Code Execution Vulnerability Important 8 Microsoft Configuration Manager - - -
CVE-2025-49713 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Important 8.8 Microsoft Edge (Chromium-based) - - -
CVE-2025-49753 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49756 Office Developer Platform Security Feature Bypass Vulnerability Important 3.3 Office Developer Platform - - -
CVE-2025-49760 Windows Storage Spoofing Vulnerability Moderate 3.5 Windows Storage - - -
CVE-2025-53771 Microsoft SharePoint Server Spoofing Vulnerability Important 6.5 Microsoft Office SharePoint - - -
CVE-2025-47973 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability Important 7.8 Virtual Hard Disk (VHDX) - - -
CVE-2025-47975 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability Important 7 Windows SSDP Service - - -
CVE-2025-47978 Windows Kerberos Denial of Service Vulnerability Important 6.5 Windows Kerberos - - -
CVE-2025-47980 Windows Imaging Component Information Disclosure Vulnerability Critical 6.2 Windows Imaging Component - - -
CVE-2025-47981 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability Critical 9.8 Windows SPNEGO Extended Negotiation - - -
CVE-2025-47982 Windows Storage VSP Driver Elevation of Privilege Vulnerability Important 7.8 Windows Storage VSP Driver - - -
CVE-2025-47996 Windows MBT Transport Driver Elevation of Privilege Vulnerability Important 7.8 Windows MBT Transport driver - - -
CVE-2025-47998 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-48000 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability Important 7.8 Windows Connected Devices Platform Service - - -
CVE-2025-48001 BitLocker Security Feature Bypass Vulnerability Important 6.8 Windows BitLocker - - -
CVE-2025-48002 Windows Hyper-V Information Disclosure Vulnerability Important 5.7 Role: Windows Hyper-V - - -
CVE-2025-48003 BitLocker Security Feature Bypass Vulnerability Important 6.8 Windows BitLocker - - -
CVE-2025-48799 Windows Update Service Elevation of Privilege Vulnerability Important 7.8 Windows Update Service - - -
CVE-2025-48800 BitLocker Security Feature Bypass Vulnerability Important 6.8 Windows BitLocker - - -
CVE-2025-48802 Windows SMB Server Spoofing Vulnerability Important 6.5 Windows SMB - - -
CVE-2025-48803 Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability Important 6.7 Windows Virtualization-Based Security (VBS) Enclave - - -
CVE-2025-48804 BitLocker Security Feature Bypass Vulnerability Important 6.8 Windows BitLocker - - -
CVE-2025-48805 Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability Important 7.8 Microsoft MPEG-2 Video Extension - - -
CVE-2025-48806 Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability Important 7.8 Microsoft MPEG-2 Video Extension - - -
CVE-2025-48808 Windows Kernel Information Disclosure Vulnerability Important 5.5 Windows Kernel - - -
CVE-2025-48809 Windows Secure Kernel Mode Information Disclosure Vulnerability Important 5.5 Windows Kernel - - -
CVE-2025-48810 Windows Secure Kernel Mode Information Disclosure Vulnerability Important 5.5 Windows Secure Kernel Mode - - -
CVE-2025-48811 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability Important 6.7 Windows Virtualization-Based Security (VBS) Enclave - - -
CVE-2025-48814 Remote Desktop Licensing Service Security Feature Bypass Vulnerability Important 7.5 Windows Remote Desktop Licensing Service - - -
CVE-2025-48815 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability Important 7.8 Windows SSDP Service - - -
CVE-2025-48816 HID Class Driver Elevation of Privilege Vulnerability Important 7.8 HID class driver - - -
CVE-2025-48817 Remote Desktop Client Remote Code Execution Vulnerability Important 8.8 Remote Desktop Client - - -
CVE-2025-48818 BitLocker Security Feature Bypass Vulnerability Important 6.8 Windows BitLocker - - -
CVE-2025-48819 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability Important 7.1 Windows Universal Plug and Play (UPnP) Device Host - - -
CVE-2025-48820 Windows AppX Deployment Service Elevation of Privilege Vulnerability Important 7.8 Windows AppX Deployment Service - - -
CVE-2025-48821 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability Important 7.1 Windows Universal Plug and Play (UPnP) Device Host - - -
CVE-2025-48822 Windows Hyper-V Discrete Device Assignment (DDA) Remote Code Execution Vulnerability Critical 8.6 Role: Windows Hyper-V - - -
CVE-2025-48823 Windows Cryptographic Services Information Disclosure Vulnerability Important 5.9 Windows Cryptographic Services - - -
CVE-2025-49659 Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability Important 7.8 Windows TDX.sys - - -
CVE-2025-49660 Windows Event Tracing Elevation of Privilege Vulnerability Important 7.8 Windows Event Tracing - - -
CVE-2025-49663 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49664 Windows User-Mode Driver Framework Host Information Disclosure Vulnerability Important 5.5 Windows User-Mode Driver Framework Host - - -
CVE-2025-49665 Workspace Broker Elevation of Privilege Vulnerability Important 7.8 Workspace Broker - - -
CVE-2025-49666 Windows Server Setup and Boot Event Collection Remote Code Execution Vulnerability Important 7.2 Windows Kernel - - -
CVE-2025-49667 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Important 7.8 Windows Win32K - ICOMP - - -
CVE-2025-49668 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49669 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49673 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49675 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Important 7.8 Kernel Streaming WOW Thunk Service Driver - - -
CVE-2025-49678 NTFS Elevation of Privilege Vulnerability Important 7 Windows NTFS - - -
CVE-2025-49679 Windows Shell Elevation of Privilege Vulnerability Important 7.8 Windows Shell - - -
CVE-2025-49680 Windows Performance Recorder (WPR) Denial of Service Vulnerability Important 7.3 Windows Performance Recorder - - -
CVE-2025-49681 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability Important 6.5 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49682 Windows Media Elevation of Privilege Vulnerability Important 7.3 Windows Media - - -
CVE-2025-49683 Microsoft Virtual Hard Disk Remote Code Execution Vulnerability Low 7.8 Virtual Hard Disk (VHDX) - - -
CVE-2025-49684 Windows Storage Port Driver Information Disclosure Vulnerability Important 5.5 Storage Port Driver - - -
CVE-2025-49685 Windows Search Service Elevation of Privilege Vulnerability Important 7 Microsoft Windows Search Component - - -
CVE-2025-49693 Microsoft Brokering File System Elevation of Privilege Vulnerability Important 7.8 Microsoft Brokering File System - - -
CVE-2025-49695 Microsoft Office Remote Code Execution Vulnerability Critical 8.4 Microsoft Office - - -
CVE-2025-49696 Microsoft Office Remote Code Execution Vulnerability Critical 8.4 Microsoft Office - - -
CVE-2025-49697 Microsoft Office Remote Code Execution Vulnerability Critical 8.4 Microsoft Office - - -
CVE-2025-49698 Microsoft Word Remote Code Execution Vulnerability Critical 7.8 Microsoft Office Word - - -
CVE-2025-49699 Microsoft Office Remote Code Execution Vulnerability Important 7 Microsoft Office - - -
CVE-2025-49700 Microsoft Word Remote Code Execution Vulnerability Important 7.8 Microsoft Office Word - - -
CVE-2025-49701 Microsoft SharePoint Remote Code Execution Vulnerability Important 8.8 Microsoft Office SharePoint - - -
CVE-2025-49702 Microsoft Office Remote Code Execution Vulnerability Critical 7.8 Microsoft Office - - -
CVE-2025-49703 Microsoft Word Remote Code Execution Vulnerability Critical 7.8 Microsoft Office Word - - -
CVE-2025-49704 Microsoft SharePoint Remote Code Execution Vulnerability Critical 8.8 Microsoft Office SharePoint - - -
CVE-2025-49705 Microsoft PowerPoint Remote Code Execution Vulnerability Important 7.8 Microsoft Office PowerPoint - - -
CVE-2025-49706 Microsoft SharePoint Server Spoofing Vulnerability Important 6.5 Microsoft Office SharePoint - - -
CVE-2025-49714 Visual Studio Code Python Extension Remote Code Execution Vulnerability Important 7.8 Visual Studio Code - Python extension - - -
CVE-2025-49718 Microsoft SQL Server Information Disclosure Vulnerability Important 7.5 SQL Server - - -
CVE-2025-49722 Windows Print Spooler Denial of Service Vulnerability Important 5.7 Windows Print Spooler Components - - -
CVE-2025-49724 Windows Connected Devices Platform Service Remote Code Execution Vulnerability Important 8.8 Windows Connected Devices Platform Service - - -
CVE-2025-49725 Windows Notification Elevation of Privilege Vulnerability Important 7.8 Windows Notification - - -
CVE-2025-49727 Win32k Elevation of Privilege Vulnerability Important 7 Windows Win32K - GRFX - - -
CVE-2025-49729 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Important 8.8 Windows Routing and Remote Access Service (RRAS) - - -
CVE-2025-49730 Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability Important 7.8 Microsoft Windows QoS scheduler - - -
CVE-2025-49732 Windows Graphics Component Elevation of Privilege Vulnerability Important 7.8 Microsoft Graphics Component - - -
CVE-2025-49733 Win32k Elevation of Privilege Vulnerability Important 7.8 Windows Win32K - ICOMP - - -
CVE-2025-47999 Windows Hyper-V Denial of Service Vulnerability Important 6.8 Role: Windows Hyper-V - - -
CVE-2025-49737 Microsoft Teams Elevation of Privilege Vulnerability Important 7 Microsoft Teams - - -
CVE-2025-49738 Microsoft PC Manager Elevation of Privilege Vulnerability Important 7.8 Microsoft PC Manager - - -
CVE-2025-49739 Visual Studio Elevation of Privilege Vulnerability Important 8.8 Visual Studio - - -
CVE-2025-49740 Windows SmartScreen Security Feature Bypass Vulnerability Important 8.8 Windows SmartScreen - - -
CVE-2025-49741 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Important 7.5 Microsoft Edge (Chromium-based) - - -
CVE-2025-49742 Windows Graphics Component Remote Code Execution Vulnerability Important 7.8 Microsoft Graphics Component - - -
CVE-2025-49744 Windows Graphics Component Elevation of Privilege Vulnerability Important 7 Microsoft Graphics Component - - -
CVE-2025-49747 Azure Machine Learning Elevation of Privilege Vulnerability Critical 8.8 Azure Machine Learning - - -
CVE-2025-49746 Azure Machine Learning Elevation of Privilege Vulnerability Critical 8.8 Azure Machine Learning - - -
CVE-2025-47995 Azure Machine Learning Elevation of Privilege Vulnerability Critical 8.8 Azure Machine Learning - - -
CVE-2025-47158 Azure DevOps Server Elevation of Privilege Vulnerability Critical 9 Azure DevOps - - -
CVE-2025-53762 Microsoft Purview Elevation of Privilege Vulnerability Critical 9.9 Microsoft Purview - - -
CVE-2025-53770 Microsoft SharePoint Server Remote Code Execution Vulnerability Critical 9.8 Microsoft Office SharePoint Yes - -
CVE-2025-47988 Azure Monitor Agent Remote Code Execution Vulnerability Important 7.5 Azure Monitor Agent - - -

Threat Categories 7

Threat Category CVEs Critical
Elevation of Privilege 58 5
Remote Code Execution 42 11
Information Disclosure 17 1
Security Feature Bypass 8 -
Denial of Service 6 -
Spoofing 5 -
Tampering 1 -

Affected Products 72

Product CVEs Exploited
Windows Routing and Remote Access Service (RRAS) 16 -
Microsoft Office 6 -
Microsoft Office SharePoint 5 1
Windows BitLocker 5 -
Virtual Hard Disk (VHDX) 4 -
Windows Kernel 4 -
Azure Machine Learning 3 -
Microsoft Brokering File System 3 -
Microsoft Graphics Component 3 -
Microsoft Input Method Editor (IME) 3 -
Microsoft Office Word 3 -
Role: Windows Hyper-V 3 -
SQL Server 3 -
Windows SSDP Service 3 -
Windows Virtualization-Based Security (VBS) Enclave 3 -
Microsoft Edge (Chromium-based) 2 -
Microsoft MPEG-2 Video Extension 2 -
Microsoft Office Excel 2 -
Microsoft PC Manager 2 -
Microsoft Teams 2 -
Remote Desktop Client 2 -
Windows Connected Devices Platform Service 2 -
Windows Event Tracing 2 -
Windows Media 2 -
Windows Notification 2 -
Windows TDX.sys 2 -
Windows Universal Plug and Play (UPnP) Device Host 2 -
Windows Win32K - ICOMP 2 -
Azure DevOps 1 -
Azure Monitor Agent 1 -
Capability Access Management Service (camsvc) 1 -
HID class driver 1 -
Kernel Streaming WOW Thunk Service Driver 1 -
Microsoft Configuration Manager 1 -
Microsoft Office PowerPoint 1 -
Microsoft Purview 1 -
Microsoft Windows QoS scheduler 1 -
Microsoft Windows Search Component 1 -
Office Developer Platform 1 -
Service Fabric 1 -
Storage Port Driver 1 -
Universal Print Management Service 1 -
Visual Studio 1 -
Visual Studio Code - Python extension 1 -
Windows Ancillary Function Driver for WinSock 1 -
Windows AppX Deployment Service 1 -
Windows Cred SSProvider Protocol 1 -
Windows Cryptographic Services 1 -
Windows Fast FAT Driver 1 -
Windows GDI 1 -
Windows Imaging Component 1 -
Windows KDC Proxy Service (KPSSVC) 1 -
Windows Kerberos 1 -
Windows MBT Transport driver 1 -
Windows NTFS 1 -
Windows Netlogon 1 -
Windows Performance Recorder 1 -
Windows Print Spooler Components 1 -
Windows Remote Desktop Licensing Service 1 -
Windows SMB 1 -
Windows SPNEGO Extended Negotiation 1 -
Windows Secure Kernel Mode 1 -
Windows Shell 1 -
Windows SmartScreen 1 -
Windows StateRepository API 1 -
Windows Storage 1 -
Windows Storage VSP Driver 1 -
Windows TCP/IP 1 -
Windows Update Service 1 -
Windows User-Mode Driver Framework Host 1 -
Windows Win32K - GRFX 1 -
Workspace Broker 1 -