Vulnerability index

Browse CVEs

458 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2025-59286 Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio… 365 Copilot Chat Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.8 CVE-2025-59246EPSS 7% Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002025-10-09 CRITICAL 9.8 CVE-2025-59247 Azure PlayFab Elevation of Privilege Vulnerability Azure Playfab No fix yet Fix from $2,3002025-10-09 CRITICAL 9.6 CVE-2025-59218 Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002025-10-09 CRITICAL 9.3 CVE-2025-59252 Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio… 365 Word Copilot Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.3 CVE-2025-59272 Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information… 365 Copilot Chat Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.3 CVE-2025-55321 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoo… Azure Monitor Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.8 CVE-2025-55319 Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network. Visual Studio Code 1.104.0+ Fix from $2,3002025-09-12 CRITICAL 9.8 CVE-2025-55232 Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. Hpc Pack 6.3.8352+ Fix from $2,3002025-09-09 CRITICAL 9.8 CVE-2025-55234EPSS 20% SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could p… Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $2,3002025-09-09 CRITICAL 9.0 CVE-2025-55244 Azure Bot Service Elevation of Privilege Vulnerability Azure Ai Bot Service No fix yet Fix from $2,3002025-09-04 CRITICAL 10.0 CVE-2025-55241 Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002025-09-04 CRITICAL 9.8 CVE-2025-54914 Azure Networking Elevation of Privilege Vulnerability Azure Networking No fix yet Fix from $2,3002025-09-04 CRITICAL 9.8 CVE-2025-53795 Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network. Pc Manager Mitigation only Fix from $2,3002025-08-21 CRITICAL 9.8 CVE-2025-53763 Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. Purview Data Governance No fix yet Fix from $2,3002025-08-21 CRITICAL 9.8 CVE-2025-53766EPSS 7% Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. 365 Copilot 10.0.10240.21100 / 10.0.14393.8330+ Fix from $2,3002025-08-12 CRITICAL 9.1 CVE-2025-50171 Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. Windows Server 2022 10.0.20348.3989 / 10.0.25398.1791+ Fix from $2,3002025-08-12 CRITICAL 9.8 CVE-2025-50165EPSS 10% Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. Windows 11 24h2 10.0.26100.4851+ Fix from $2,3002025-08-12 CRITICAL 10.0 CVE-2025-53767 Azure OpenAI Elevation of Privilege Vulnerability Azure Openai No fix yet Fix from $2,3002025-08-07 CRITICAL 9.1 CVE-2025-53792 Azure Portal Elevation of Privilege Vulnerability Azure Portal No fix yet Fix from $2,3002025-08-07 CRITICAL 9.8 CVE-2025-53770 KEVEPSS 100% Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsof… Sharepoint Server 16.0.18526.20508+ Fix from $2,3002025-07-20 CRITICAL 9.9 CVE-2025-53762 Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network. Purview No fix yet Fix from $2,3002025-07-18 CRITICAL 9.0 CVE-2025-47158 Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. Azure Devops Mitigation only Fix from $2,3002025-07-18 CRITICAL 9.8 CVE-2025-47981EPSS 32% Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $2,3002025-07-08 CRITICAL 9.8 CVE-2025-47966 Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. Power Automate For Desktop No fix yet Fix from $2,3002025-06-05 CRITICAL 9.8 CVE-2025-30387 Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a … Azure Ai Document Intelligence Studio Mitigation only Fix from $2,3002025-05-13 CRITICAL 9.8 CVE-2025-29813 Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. Azure Devops Mitigation only Fix from $2,3002025-05-08 CRITICAL 9.8 CVE-2025-29972 Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. Azure Storage Resource Provider Mitigation only Fix from $2,3002025-05-08 CRITICAL 9.8 CVE-2025-47732 Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. Dataverse Mitigation only Fix from $2,3002025-05-08 CRITICAL 9.8 CVE-2025-30389 Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. Azure Ai Bot Service Mitigation only Fix from $2,3002025-04-30