Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
4933
Current result set after filter and search.
Exploited Flagged
4189
Rows with a non-empty exploitation signal.
Distinct CWE
162
Unique weakness classes in this view.
Modules
1528
Unique inferred driver or component labels.
Reset
Release Month
September 2025
41 CVE | last update 1 day(s) ago
Release 2025-09-09 Patch Tuesday Count 11
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-53797
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-53796
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-55225
Windows Routing and Remote Access Service (RRAS)
Exploitation Less Likely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-54097
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-54096
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-54095
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-53805
HTTP.sys
Exploitation Unlikely
HTTP.sys Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Rutuja Shirali with Microsoft
Yesayi Hovnanyan with Microsoft
Matthew Cox with Microsoft
CVE-2025-54113
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-54894
Local Security Authority Subsystem Service
Exploitation Less Likely
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-09-09 No
Reported By
Anonymous
CVE-2025-54916
Windows NTFS
Exploitation More Likely
Windows NTFS Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-09-09 No
CVE-2025-54099
Windows Ancillary Function Driver for WinSock
Exploitation Less Likely
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-09-09 No
Reported By
haowei yan with jingdong dawnslab
Angelboy (@scwuaptx) with DEVCORE
Release 2025-09-04 Other / OOB Count 7
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2010-4756
The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a
No latest release note
The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.
No CVSS vector published
2025-09-04 - -
CVE-2018-1000215
Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in
No latest release note
Dave Gamble cJSON version 1.7.6 and earlier contains a CWE-772 vulnerability in cJSON library that can result in Denial of Service
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-09-04 - -
CVE-2025-49795
Libxml: null pointer dereference leads to
No latest release note
Libxml: null pointer dereference leads to denial of service (dos)
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-09-04 - -
CVE-2024-25177
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to
No latest release note
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS).
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-09-04 - -
CVE-2025-23266
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering
No latest release note
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
CVSS vector: AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
2025-09-04 - -
CVE-2025-48964
ping in iputils before 20250602 allows a
No latest release note
ping in iputils before 20250602 allows a denial of service (application error in adaptive ping mode or incorrect data collection) via a crafted ICMP Echo Reply packet, because a zero timestamp can lead to large intermediate values that have an integer overflow when squared during statistics calculations. NOTE: this issue exists because of an incomplete fix for CVE-2025-47268 (that fix was only about timestamp calculations, and it did not account for a specific scenario where the original timestamp in the ICMP payload is zero).
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
2025-09-04 - -
CVE-2017-7718
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a
No latest release note
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions.
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2025-09-04 - -
Release 2025-09-03 Other / OOB Count 23
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-24791
net/http
No latest release note
Denial of service due to improper 100-continue handling in net/http
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2023-39326
net/http
No latest release note
Denial of service via chunk extensions in net/http
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
2025-09-03 - -
CVE-2019-14249
dwarf_elf_load_headers.c in libdwarf before 2019-07-05 allows attackers to cause a
No latest release note
dwarf_elf_load_headers.c in libdwarf before 2019-07-05 allows attackers to cause a denial of service
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2014-5461
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a
No latest release note
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
No CVSS vector published
2025-09-03 - -
CVE-2023-49556
Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a
No latest release note
Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2023-49558
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a
No latest release note
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2023-49557
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a
No latest release note
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2023-49555
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a
No latest release note
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2024-30251
aiohttp
No latest release note
Denial of service when trying to parse malformed POST requests in aiohttp
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2025-32049
Libsoup
No latest release note
Libsoup: denial of service attack to websocket server
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2024-11407
gRPC-C++
No latest release note
Denial of Service through Data corruption in gRPC-C++
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2025-31160
atop through 2.11.0 allows local users to cause a
No latest release note
atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or possibly have unspecified other impact by running certain types of unprivileged processes while a different user runs atop.
CVSS vector: AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
2025-09-03 - -
CVE-2023-49554
Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a
No latest release note
Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2023-42364
A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a
No latest release note
A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2019-20633
GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a
No latest release note
GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2025-4287
PyTorch nccl.py torch.cuda.nccl.reduce
No latest release note
PyTorch nccl.py torch.cuda.nccl.reduce denial of service
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
2025-09-03 - -
CVE-2009-5063
Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a
No latest release note
Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length. NOTE: this is due to an incomplete fix for CVE-2006-7244.
No CVSS vector published
2025-09-03 - -
CVE-2010-2249
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a
No latest release note
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2025-24294
The attack vector is a potential
No latest release note
The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2024-57075
A prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a
No latest release note
A prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2016-8681
The _dwarf_get_abbrev_for_code function in dwarf_util.c in libdwarf 20161001 and earlier allows remote attackers to cause a
No latest release note
The _dwarf_get_abbrev_for_code function in dwarf_util.c in libdwarf 20161001 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) by calling the dwarfdump command on a crafted file.
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2025-09-03 - -
CVE-2023-4458
Kernel: ksmbd: smb2_open out-of-bounds read
No latest release note
Kernel: ksmbd: smb2_open out-of-bounds read information disclosure vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
2025-09-03 - -
CVE-2023-46847
Squid
No latest release note
Squid: denial of service in http digest authentication
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
2025-09-03 - -
Release Month
August 2025
9 CVE | last update 1 day(s) ago
Release 2025-08-21 Other / OOB Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-55230
Windows MBT Transport Driver
Exploitation Unlikely
Windows MBT Transport Driver Elevation of Privilege Vulnerability
CVSS vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-08-21 No
Reported By
CVE-2025-55231
Windows Storage-based Management Service
Exploitation Unlikely
Windows Storage-based Management Service Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-08-21 No
Reported By
CVE-2025-53795
Microsoft PC Manager
N/A
Microsoft PC Manager Elevation of Privilege Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
2025-08-21 No
Reported By
Adri Bonilla Martin (k0x)
Release 2025-08-14 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-7458
SQLite integer overflow in key info allocation may lead to
No latest release note
SQLite integer overflow in key info allocation may lead to information disclosure.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
2025-08-14 - -
Release 2025-08-12 Patch Tuesday Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2025-48807
Windows Hyper-V
Exploitation Less Likely
Windows Hyper-V Remote Code Execution Vulnerability
CVSS vector: AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2025-08-12 No
Reported By
QWangWang & zcgonvh
CVE-2025-53719
Windows Routing and Remote Access Service (RRAS)
Exploitation Less Likely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-08-12 No
Reported By
Anonymous
CVE-2025-53153
Windows Routing and Remote Access Service (RRAS)
Exploitation Less Likely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-08-12 No
Reported By
Anonymous
CVE-2025-53148
Windows Routing and Remote Access Service (RRAS)
Exploitation Less Likely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-08-12 No
Reported By
Anonymous
CVE-2025-53138
Windows Routing and Remote Access Service (RRAS)
Exploitation Unlikely
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
2025-08-12 No
Reported By
Anonymous
Prev Page 15 / 99 | rows 701-750 of 4933 Next