Vulnerability index

Browse CVEs

611 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2025-62455 Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8688 / 10.0.17763.8146+ Fix from $1,9502025-12-09 HIGH 8.8 CVE-2025-62222 Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthoriz… Github Copilot Chat 0.32.5+ Fix from $1,9502025-11-11 HIGH 8.1 CVE-2025-59250 Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network. Jdbc Driver For Sql Server 10.2.4 / 11.2.4+ Fix from $1,9502025-10-14 HIGH 7.5 CVE-2025-59248 Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. Exchange Server 15.02.2562.029+ Fix from $1,9502025-10-14 HIGH 8.8 CVE-2025-59228 Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20262+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59207 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7919 / 10.0.19044.6456+ Fix from $1,9502025-10-14 MEDIUM 5.0 CVE-2025-59198 Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 HIGH 7.8 CVE-2025-59187 Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 MEDIUM 5.5 CVE-2025-59190 Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 HIGH 8.8 CVE-2025-58716 Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-55692 Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 MEDIUM 6.5 CVE-2025-53809 Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. Windows 11 24h2 10.0.26100.6508+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-25005 Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. Exchange Server 15.02.2562.020+ Fix from $1,6002025-08-12 MEDIUM 5.6 CVE-2025-47182 Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. Edge Chromium 138.0.3351.55+ Fix from $1,6002025-07-11 HIGH 7.5 CVE-2025-49719EPSS 11% Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network. Sql Server 2016 13.0.6460.7 / 13.0.7055.9+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47982 Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47968 Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. Autoupdate 4.79+ Fix from $1,9502025-06-10 MEDIUM 6.7 CVE-2025-47171 Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,6002025-06-10 HIGH 7.8 CVE-2025-32706 KEV Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 MEDIUM 6.5 CVE-2025-29968 Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network. Windows Server 2008 10.0.14393.8066 / 10.0.17763.7314+ Fix from $1,6002025-05-13 MEDIUM 5.5 CVE-2025-29955 Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally. Windows 11 24h2 10.0.25398.1611 / 10.0.26100.4061+ Fix from $1,6002025-05-13 HIGH 7.5 CVE-2025-30391 Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network. Dynamics 365 Customer Service Mitigation only Fix from $1,9502025-04-30 MEDIUM 5.5 CVE-2025-29821 Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally. Dynamics 365 Business Central 2023 23.18.32409 / 24.12.32447+ Fix from $1,6002025-04-08 HIGH 7.8 CVE-2025-29811 Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.5189 / 10.0.22631.5189+ Fix from $1,9502025-04-08 HIGH 8.6 CVE-2025-27737 Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-27731 Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7136 / 10.0.19044.5737+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-27489 Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally. Azure Stack Hci 22h2 10.0.20348.3328 / 10.0.25398.1486+ Fix from $1,9502025-04-08 HIGH 8.8 CVE-2025-26647 Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network. Windows Server 2008 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-24058 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7136 / 10.0.19044.5737+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-24060 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7136 / 10.0.19044.5737+ Fix from $1,9502025-04-08