Vulnerability index

Browse CVEs

458 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-30392 Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. Azure Ai Bot Service Mitigation only Fix from $2,3002025-04-30 CRITICAL 9.8 CVE-2025-26683 Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network. Azure Playwright Mitigation only Fix from $2,3002025-03-31 CRITICAL 9.8 CVE-2025-24989 KEV An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing th… Power Pages Patch available Fix from $2,3002025-02-19 CRITICAL 9.8 CVE-2025-21355 Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network Bing Patch available Fix from $2,3002025-02-19 CRITICAL 9.0 CVE-2025-21198 Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability Hpc Pack 2016 6.3.8328.0 / 2016.3+ Fix from $2,3002025-02-11 CRITICAL 9.8 CVE-2025-21311 Windows NTLM V1 Elevation of Privilege Vulnerability Windows 11 24h2 10.0.25398.1369 / 10.0.26100.2894+ Fix from $2,3002025-01-14 CRITICAL 9.8 CVE-2025-21307 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $2,3002025-01-14 CRITICAL 9.8 CVE-2025-21298EPSS 81% Windows OLE Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $2,3002025-01-14 CRITICAL 9.8 CVE-2024-42004 A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage… Teams No fix yet Fix from $2,3002024-12-18 CRITICAL 9.1 CVE-2024-41165 A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leadin… Word No fix yet Fix from $2,3002024-12-18 CRITICAL 9.1 CVE-2024-42220 A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges… Outlook No fix yet Fix from $2,3002024-12-18 CRITICAL 9.1 CVE-2024-43106 A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, lead… Excel No fix yet Fix from $2,3002024-12-18 CRITICAL 9.8 CVE-2024-41138 A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.10… Teams No fix yet Fix from $2,3002024-12-18 CRITICAL 9.8 CVE-2024-41145 A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A speciall… Teams No fix yet Fix from $2,3002024-12-18 CRITICAL 9.1 CVE-2024-39804 A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privil… Powerpoint No fix yet Fix from $2,3002024-12-18 CRITICAL 9.8 CVE-2024-49147 Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver. Update Catalog Mitigation only Fix from $2,3002024-12-12 CRITICAL 9.8 CVE-2024-49112EPSS 71% Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.20857 / 10.0.14393.7606+ Fix from $2,3002024-12-12 CRITICAL 9.8 CVE-2024-49052 Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. Azure Functions Mitigation only Fix from $2,3002024-11-26 CRITICAL 9.8 CVE-2024-49035 KEV An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. Partner Center Mitigation only Fix from $2,3002024-11-26 CRITICAL 9.6 CVE-2024-49038 Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation… Copilot Studio Mitigation only Fix from $2,3002024-11-26 CRITICAL 9.8 CVE-2024-43639EPSS 9% Windows KDC Proxy Remote Code Execution Vulnerability Windows Server 2012 10.0.14393.7515 / 10.0.17763.6532+ Fix from $2,3002024-11-12 CRITICAL 9.9 CVE-2024-43602 Azure CycleCloud Remote Code Execution Vulnerability Azure Cyclecloud 8.6.5+ Fix from $2,3002024-11-12 CRITICAL 9.8 CVE-2024-43498 .NET and Visual Studio Remote Code Execution Vulnerability .net 17.6.21 / 17.8.16+ Fix from $2,3002024-11-12 CRITICAL 9.8 CVE-2024-43566 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Edge Chromium 130.0.2849.46+ Fix from $2,3002024-10-17 CRITICAL 9.1 CVE-2024-43591 Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability Azure Command Line Interface 2.65.0+ Fix from $2,3002024-10-08 CRITICAL 9.8 CVE-2024-43488 Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code ex… Visual Studio Code Patch available Fix from $2,3002024-10-08 CRITICAL 9.8 CVE-2024-43468 KEVEPSS 62% Microsoft Configuration Manager Remote Code Execution Vulnerability Configuration Manager 2403 No fix yet Fix from $2,3002024-10-08 CRITICAL 9.0 CVE-2024-38124 Windows Netlogon Elevation of Privilege Vulnerability Windows Server 2008 10.0.14393.7428 / 10.0.17763.6414+ Fix from $2,3002024-10-08 CRITICAL 9.8 CVE-2024-38183 An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network. Groupme Patch available Fix from $2,3002024-09-17 CRITICAL 9.8 CVE-2024-43491EPSS 12% Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Win… Windows 10 1507 10.0.10240.20766+ Fix from $2,3002024-09-10