Vulnerability index

Browse CVEs

458 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

365 Copilot Chat CRITICAL 9.3
CVE-2025-59286

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio…

Mitigation only
Fix from $2,300 2025-10-09
Entra Id CRITICAL 9.8
CVE-2025-59246EPSS 7%

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-10-09
Azure Playfab CRITICAL 9.8
CVE-2025-59247

Azure PlayFab Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-10-09
Entra Id CRITICAL 9.6
CVE-2025-59218

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-10-09
365 Word Copilot CRITICAL 9.3
CVE-2025-59252

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio…

Mitigation only
Fix from $2,300 2025-10-09
365 Copilot Chat CRITICAL 9.3
CVE-2025-59272

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information…

Mitigation only
Fix from $2,300 2025-10-09
Azure Monitor CRITICAL 9.3
CVE-2025-55321

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoo…

Mitigation only
Fix from $2,300 2025-10-09
Visual Studio Code CRITICAL 9.8
CVE-2025-55319

Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.

Fix: 1.104.0+
Fix from $2,300 2025-09-12
Hpc Pack CRITICAL 9.8
CVE-2025-55232

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network.

Fix: 6.3.8352+
Fix from $2,300 2025-09-09
Windows 10 1507 CRITICAL 9.8
CVE-2025-55234EPSS 20%

SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could p…

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $2,300 2025-09-09
Azure Ai Bot Service CRITICAL 9.0
CVE-2025-55244

Azure Bot Service Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-09-04
Entra Id CRITICAL 10.0
CVE-2025-55241

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-09-04
Azure Networking CRITICAL 9.8
CVE-2025-54914

Azure Networking Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-09-04
Pc Manager CRITICAL 9.8
CVE-2025-53795

Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-08-21
Purview Data Governance CRITICAL 9.8
CVE-2025-53763

Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-08-21
365 Copilot CRITICAL 9.8
CVE-2025-53766EPSS 7%

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $2,300 2025-08-12
Windows Server 2022 CRITICAL 9.1
CVE-2025-50171

Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.20348.3989 / 10.0.25398.1791+
Fix from $2,300 2025-08-12
Windows 11 24h2 CRITICAL 9.8
CVE-2025-50165EPSS 10%

Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Fix: 10.0.26100.4851+
Fix from $2,300 2025-08-12
Azure Openai CRITICAL 10.0
CVE-2025-53767

Azure OpenAI Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-08-07
Azure Portal CRITICAL 9.1
CVE-2025-53792

Azure Portal Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-08-07
Sharepoint Server CRITICAL 9.8
CVE-2025-53770 KEVEPSS 100%

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsof…

Fix: 16.0.18526.20508+
Fix from $2,300 2025-07-20
Purview CRITICAL 9.9
CVE-2025-53762

Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-07-18
Azure Devops CRITICAL 9.0
CVE-2025-47158

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-07-18
Windows 10 1507 CRITICAL 9.8
CVE-2025-47981EPSS 32%

Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $2,300 2025-07-08
Power Automate For Desktop CRITICAL 9.8
CVE-2025-47966

Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-06-05
Azure Ai Document Intelligence Studio CRITICAL 9.8
CVE-2025-30387

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a …

Mitigation only
Fix from $2,300 2025-05-13
Azure Devops CRITICAL 9.8
CVE-2025-29813

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-05-08
Azure Storage Resource Provider CRITICAL 9.8
CVE-2025-29972

Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.

Mitigation only
Fix from $2,300 2025-05-08
Dataverse CRITICAL 9.8
CVE-2025-47732

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2025-05-08
Azure Ai Bot Service CRITICAL 9.8
CVE-2025-30389

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-04-30