Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Windows 11 24h2 HIGH 7.8
CVE-2025-55694

Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.6899 / 10.0.26200.6899+
Fix from $1,950 2025-10-14
Visual Studio 2017 HIGH 7.3
CVE-2025-55240

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Fix: 15.9.77 / 16.11.52+
Fix from $1,950 2025-10-14
Azure Connected Machine Agent HIGH 7.0
CVE-2025-47989

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.57+
Fix from $1,950 2025-10-14
Powershell HIGH 7.3
CVE-2025-25004

Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

Fix: 7.4.13 / 7.5.4+
Fix from $1,950 2025-10-14
Entra Id CRITICAL 9.6
CVE-2025-59218

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-10-09
Windows 10 1507 HIGH 7.3
CVE-2025-54116

Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,950 2025-09-09
Windows 10 1507 HIGH 7.8
CVE-2025-54098

Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,950 2025-09-09
Azure Connected Machine Agent HIGH 7.8
CVE-2025-49692

Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.49+
Fix from $1,950 2025-09-09
Azure Ai Bot Service CRITICAL 9.0
CVE-2025-55244

Azure Bot Service Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-09-04
Azure Networking CRITICAL 9.8
CVE-2025-54914

Azure Networking Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-09-04
Dynamics 365 HIGH 7.5
CVE-2025-55238

Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability

No fix yet
Fix from $1,950 2025-09-04
Purview Data Governance CRITICAL 9.8
CVE-2025-53763

Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-08-21
Azure File Sync HIGH 7.8
CVE-2025-53729

Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.

Fix: 18.3.0.0 / 19.2.0.0+
Fix from $1,950 2025-08-12
Ecesv6 Series Azure Vm Firmware MEDIUM 5.5
CVE-2025-49707

Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.

No fix yet
Fix from $1,600 2025-08-12
Sql Server 2016 HIGH 8.8
CVE-2025-24999

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Fix: 13.0.6465.1 / 13.0.7060.1+
Fix from $1,950 2025-08-12
Remote Desktop Client HIGH 8.8
CVE-2025-48817

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 1.2.6353 / 2.0.559.0+
Fix from $1,950 2025-07-08
Windows 11 24h2 HIGH 7.8
CVE-2025-47993

Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.25398.1732 / 10.0.26100.4652+
Fix from $1,950 2025-07-08
Windows Software Development Kit HIGH 7.8
CVE-2025-47962

Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.4188+
Fix from $1,950 2025-06-10
Windows 10 1507 HIGH 8.8
CVE-2025-33073 KEVEPSS 80%

Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,950 2025-06-10
Windows 10 1507 HIGH 7.5
CVE-2025-33056

Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,950 2025-06-10
Windows 10 1507 MEDIUM 5.5
CVE-2025-32722

Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,600 2025-06-10
Windows 10 1507 HIGH 7.8
CVE-2025-32714

Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,950 2025-06-10
Defender For Endpoint HIGH 7.8
CVE-2025-47161

Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

Fix: 101.25022.0002+
Fix from $1,950 2025-05-15
Azure File Sync HIGH 7.0
CVE-2025-29973

Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2025-05-13
Msagsfeedback.azurewebsites.net HIGH 7.5
CVE-2025-33072

Improper access control in Azure allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2025-05-08
Visual Studio Code MEDIUM 6.8
CVE-2025-32726

Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.

Fix: 1.99.1+
Fix from $1,600 2025-04-12
Windows 10 1507 HIGH 7.5
CVE-2025-29810

Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Visual Studio 2022 HIGH 7.3
CVE-2025-29804

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Fix: 17.8.20 / 17.10.13+
Fix from $1,950 2025-04-08
Office HIGH 7.8
CVE-2025-27744

Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2025-04-08
Windows 10 1507 MEDIUM 6.5
CVE-2025-27738

Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,600 2025-04-08