Total
521 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-47973 | 1 Microsoft | 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more | 2026-06-17 | N/A | 7.8 HIGH |
| Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. | |||||
| CVE-2025-47971 | 1 Microsoft | 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more | 2026-06-17 | N/A | 7.8 HIGH |
| Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. | |||||
| CVE-2025-47406 | 1 Qualcomm | 62 Cologne, Cologne Firmware, Fastconnect 6700 and 59 more | 2026-06-17 | N/A | 6.1 MEDIUM |
| Information Disclosure while processing IOCTL handler callbacks without verifying buffer size. | |||||
| CVE-2025-47403 | 1 Qualcomm | 514 Ar8035, Ar8035 Firmware, Cologne and 511 more | 2026-06-17 | N/A | 6.5 MEDIUM |
| Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | |||||
| CVE-2025-47402 | 1 Qualcomm | 188 Ar8035, Ar8035 Firmware, Cologne and 185 more | 2026-06-17 | N/A | 6.5 MEDIUM |
| Transient DOS when processing a received frame with an excessively large authentication information element. | |||||
| CVE-2025-47401 | 1 Qualcomm | 490 Ar8035, Ar8035 Firmware, Cologne and 487 more | 2026-06-17 | N/A | 6.5 MEDIUM |
| Transient DOS when processing target power rate tables during channel configuration. | |||||
| CVE-2025-47400 | 1 Qualcomm | 22 Pandeiro, Pandeiro Firmware, Snapdragon 8 Elite Gen 5 and 19 more | 2026-06-17 | N/A | 7.1 HIGH |
| Cryptographic issue while copying data to a destination buffer without validating its size. | |||||
| CVE-2025-47395 | 1 Qualcomm | 2 Wcn7861, Wcn7861 Firmware | 2026-06-17 | N/A | 6.5 MEDIUM |
| Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element. | |||||
| CVE-2025-47390 | 1 Qualcomm | 58 Cologne, Cologne Firmware, Fastconnect 6700 and 55 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption while preprocessing IOCTL request in JPEG driver. | |||||
| CVE-2025-47368 | 1 Qualcomm | 16 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 13 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing. | |||||
| CVE-2025-47362 | 1 Qualcomm | 76 Msm8996au, Msm8996au Firmware, Qam8255p and 73 more | 2026-06-17 | N/A | 6.1 MEDIUM |
| Information disclosure while processing message from client with invalid payload. | |||||
| CVE-2025-47331 | 1 Qualcomm | 598 Ar8031, Ar8031 Firmware, Ar8035 and 595 more | 2026-06-17 | N/A | 6.1 MEDIUM |
| Information disclosure while processing a firmware event. | |||||
| CVE-2025-47330 | 1 Qualcomm | 446 Ar8031, Ar8031 Firmware, Ar8035 and 443 more | 2026-06-17 | N/A | 5.5 MEDIUM |
| Transient DOS while parsing video packets received from the video firmware. | |||||
| CVE-2025-47328 | 1 Qualcomm | 134 Fastconnect 7800, Fastconnect 7800 Firmware, Immersive Home 3210 Platform and 131 more | 2026-06-17 | N/A | 7.5 HIGH |
| Transient DOS while processing power control requests with invalid antenna or stream values. | |||||
| CVE-2025-47326 | 1 Qualcomm | 240 Ar8035, Ar8035 Firmware, Csr8811 and 237 more | 2026-06-17 | N/A | 7.5 HIGH |
| Transient DOS while handling command data during power control processing. | |||||
| CVE-2025-47318 | 1 Qualcomm | 406 Apq8017, Apq8017 Firmware, Apq8064au and 403 more | 2026-06-17 | N/A | 7.5 HIGH |
| Transient DOS while parsing the EPTM test control message to get the test pattern. | |||||
| CVE-2025-47317 | 1 Qualcomm | 106 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 103 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption due to global buffer overflow when a test command uses an invalid payload type. | |||||
| CVE-2025-47295 | 1 Fortinet | 1 Fortios | 2026-06-17 | N/A | 3.7 LOW |
| A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions that are outside of the attacker's control. | |||||
| CVE-2025-36855 | 2026-06-17 | N/A | 8.8 HIGH | ||
| A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer. This issue affects EOL ASP.NET 6.0.0 <= 6.0.36 as represented in this CVE, as well as 8.0.0 <= 8.0.11 & <= 9.0.0 as represented in CVE-2025-21176. Additionally, if you've deployed self-contained applications https://docs.microsoft.com/dotnet/core/deploying/#self-contained-deployments-scd targeting any of the impacted versions, these applications are also vulnerable and must be recompiled and redeployed. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry. | |||||
| CVE-2025-32704 | 1 Microsoft | 4 365 Apps, Excel, Office and 1 more | 2026-06-17 | N/A | 8.4 HIGH |
| Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |||||
