Vulnerability index

Browse CVEs

458 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Azure Ai Bot Service CRITICAL 9.8
CVE-2025-30392

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-04-30
Azure Playwright CRITICAL 9.8
CVE-2025-26683

Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-03-31
Power Pages CRITICAL 9.8
CVE-2025-24989 KEV

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing th…

Patch available
Fix from $2,300 2025-02-19
Bing CRITICAL 9.8
CVE-2025-21355

Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network

Patch available
Fix from $2,300 2025-02-19
Hpc Pack 2016 CRITICAL 9.0
CVE-2025-21198

Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability

Fix: 6.3.8328.0 / 2016.3+
Fix from $2,300 2025-02-11
Windows 11 24h2 CRITICAL 9.8
CVE-2025-21311

Windows NTLM V1 Elevation of Privilege Vulnerability

Fix: 10.0.25398.1369 / 10.0.26100.2894+
Fix from $2,300 2025-01-14
Windows 10 1507 CRITICAL 9.8
CVE-2025-21307

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Fix: 10.0.10240.20890 / 10.0.14393.7699+
Fix from $2,300 2025-01-14
Windows 10 1507 CRITICAL 9.8
CVE-2025-21298EPSS 81%

Windows OLE Remote Code Execution Vulnerability

Fix: 10.0.10240.20890 / 10.0.14393.7699+
Fix from $2,300 2025-01-14
Teams CRITICAL 9.8
CVE-2024-42004

A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage…

No fix yet
Fix from $2,300 2024-12-18
Word CRITICAL 9.1
CVE-2024-41165

A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leadin…

No fix yet
Fix from $2,300 2024-12-18
Outlook CRITICAL 9.1
CVE-2024-42220

A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges…

No fix yet
Fix from $2,300 2024-12-18
Excel CRITICAL 9.1
CVE-2024-43106

A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, lead…

No fix yet
Fix from $2,300 2024-12-18
Teams CRITICAL 9.8
CVE-2024-41138

A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.10…

No fix yet
Fix from $2,300 2024-12-18
Teams CRITICAL 9.8
CVE-2024-41145

A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A speciall…

No fix yet
Fix from $2,300 2024-12-18
Powerpoint CRITICAL 9.1
CVE-2024-39804

A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privil…

No fix yet
Fix from $2,300 2024-12-18
Update Catalog CRITICAL 9.8
CVE-2024-49147

Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.

Mitigation only
Fix from $2,300 2024-12-12
Windows 10 1507 CRITICAL 9.8
CVE-2024-49112EPSS 71%

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Fix: 10.0.10240.20857 / 10.0.14393.7606+
Fix from $2,300 2024-12-12
Azure Functions CRITICAL 9.8
CVE-2024-49052

Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2024-11-26
Partner Center CRITICAL 9.8
CVE-2024-49035 KEV

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2024-11-26
Copilot Studio CRITICAL 9.6
CVE-2024-49038

Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation…

Mitigation only
Fix from $2,300 2024-11-26
Windows Server 2012 CRITICAL 9.8
CVE-2024-43639EPSS 9%

Windows KDC Proxy Remote Code Execution Vulnerability

Fix: 10.0.14393.7515 / 10.0.17763.6532+
Fix from $2,300 2024-11-12
Azure Cyclecloud CRITICAL 9.9
CVE-2024-43602

Azure CycleCloud Remote Code Execution Vulnerability

Fix: 8.6.5+
Fix from $2,300 2024-11-12
.net CRITICAL 9.8
CVE-2024-43498

.NET and Visual Studio Remote Code Execution Vulnerability

Fix: 17.6.21 / 17.8.16+
Fix from $2,300 2024-11-12
Edge Chromium CRITICAL 9.8
CVE-2024-43566

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 130.0.2849.46+
Fix from $2,300 2024-10-17
Azure Command Line Interface CRITICAL 9.1
CVE-2024-43591

Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability

Fix: 2.65.0+
Fix from $2,300 2024-10-08
Visual Studio Code CRITICAL 9.8
CVE-2024-43488

Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code ex…

Patch available
Fix from $2,300 2024-10-08
Configuration Manager 2403 CRITICAL 9.8
CVE-2024-43468 KEVEPSS 62%

Microsoft Configuration Manager Remote Code Execution Vulnerability

No fix yet
Fix from $2,300 2024-10-08
Windows Server 2008 CRITICAL 9.0
CVE-2024-38124

Windows Netlogon Elevation of Privilege Vulnerability

Fix: 10.0.14393.7428 / 10.0.17763.6414+
Fix from $2,300 2024-10-08
Groupme CRITICAL 9.8
CVE-2024-38183

An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.

Patch available
Fix from $2,300 2024-09-17
Windows 10 1507 CRITICAL 9.8
CVE-2024-43491EPSS 12%

Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Win…

Fix: 10.0.10240.20766+
Fix from $2,300 2024-09-10