Vulnerability index

Browse CVEs

611 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows 10 1607 HIGH 7.8
CVE-2025-62455

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Github Copilot Chat HIGH 8.8
CVE-2025-62222

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthoriz…

Fix: 0.32.5+
Fix from $1,950 2025-11-11
Jdbc Driver For Sql Server HIGH 8.1
CVE-2025-59250

Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.2.4 / 11.2.4+
Fix from $1,950 2025-10-14
Exchange Server HIGH 7.5
CVE-2025-59248

Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Fix: 15.02.2562.029+
Fix from $1,950 2025-10-14
Sharepoint Server HIGH 8.8
CVE-2025-59228

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19127.20262+
Fix from $1,950 2025-10-14
Windows 10 1809 HIGH 7.8
CVE-2025-59207

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7919 / 10.0.19044.6456+
Fix from $1,950 2025-10-14
Windows 10 1507 MEDIUM 5.0
CVE-2025-59198

Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-59187

Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-59190

Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows 10 1507 HIGH 8.8
CVE-2025-58716

Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-55692

Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 11 24h2 MEDIUM 6.5
CVE-2025-53809

Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

Fix: 10.0.26100.6508+
Fix from $1,600 2025-09-09
Exchange Server MEDIUM 6.5
CVE-2025-25005

Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

Fix: 15.02.2562.020+
Fix from $1,600 2025-08-12
Edge Chromium MEDIUM 5.6
CVE-2025-47182

Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

Fix: 138.0.3351.55+
Fix from $1,600 2025-07-11
Sql Server 2016 HIGH 7.5
CVE-2025-49719EPSS 11%

Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.

Fix: 13.0.6460.7 / 13.0.7055.9+
Fix from $1,950 2025-07-08
Windows 10 1607 HIGH 7.8
CVE-2025-47982

Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Autoupdate HIGH 7.8
CVE-2025-47968

Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

Fix: 4.79+
Fix from $1,950 2025-06-10
365 Apps MEDIUM 6.7
CVE-2025-47171

Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.

Mitigation only
Fix from $1,600 2025-06-10
Windows 10 1507 HIGH 7.8
CVE-2025-32706 KEV

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Windows Server 2008 MEDIUM 6.5
CVE-2025-29968

Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.

Fix: 10.0.14393.8066 / 10.0.17763.7314+
Fix from $1,600 2025-05-13
Windows 11 24h2 MEDIUM 5.5
CVE-2025-29955

Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.

Fix: 10.0.25398.1611 / 10.0.26100.4061+
Fix from $1,600 2025-05-13
Dynamics 365 Customer Service HIGH 7.5
CVE-2025-30391

Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2025-04-30
Dynamics 365 Business Central 2023 MEDIUM 5.5
CVE-2025-29821

Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.

Fix: 23.18.32409 / 24.12.32447+
Fix from $1,600 2025-04-08
Windows 11 22h2 HIGH 7.8
CVE-2025-29811

Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22621.5189 / 10.0.22631.5189+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 8.6
CVE-2025-27737

Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1809 HIGH 7.8
CVE-2025-27731

Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08
Azure Stack Hci 22h2 HIGH 7.8
CVE-2025-27489

Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.3328 / 10.0.25398.1486+
Fix from $1,950 2025-04-08
Windows Server 2008 HIGH 8.8
CVE-2025-26647

Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows 10 1809 HIGH 7.8
CVE-2025-24058

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08
Windows 10 1809 HIGH 7.8
CVE-2025-24060

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08