Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.4 CVE-2025-26678 Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally. Windows 10 1809 10.0.17763.7136 / 10.0.19044.5737+ Fix from $1,9502025-04-08 MEDIUM 6.5 CVE-2025-21197 Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't hav… Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,6002025-04-08 HIGH 8.8 CVE-2025-26645 Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.20947 / 10.0.14393.7876+ Fix from $1,9502025-03-11 HIGH 7.3 CVE-2025-24994 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.5039 / 10.0.22631.5039+ Fix from $1,9502025-03-11 HIGH 7.3 CVE-2025-24076 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.5039 / 10.0.22631.5039+ Fix from $1,9502025-03-11 CRITICAL 9.8 CVE-2025-24989 KEV An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing th… Power Pages Patch available Fix from $2,3002025-02-19 HIGH 7.3 CVE-2025-24042 Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability Visual Studio Code 1.97.1+ Fix from $1,9502025-02-11 HIGH 7.8 CVE-2025-21359 Windows Kernel Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.20915 / 10.0.14393.7785+ Fix from $1,9502025-02-11 MEDIUM 6.5 CVE-2025-21185 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Edge Chromium 132.0.2957.115+ Fix from $1,6002025-01-17 HIGH 7.3 CVE-2025-21405 Visual Studio Elevation of Privilege Vulnerability Visual Studio 2022 17.12.4+ Fix from $1,9502025-01-14 MEDIUM 5.5 CVE-2025-21340 Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability Windows 10 1809 10.0.17763.6775 / 10.0.19044.5371+ Fix from $1,6002025-01-14 MEDIUM 6.5 CVE-2025-21301 Windows Geolocation Service Information Disclosure Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $1,6002025-01-14 HIGH 8.8 CVE-2025-21293EPSS 19% Active Directory Domain Services Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $1,9502025-01-14 MEDIUM 6.1 CVE-2025-21202 Windows Recovery Environment Agent Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $1,6002025-01-14 MEDIUM 6.5 CVE-2025-21380 Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network. Azure Marketplace No fix yet Fix from $1,6002025-01-09 HIGH 8.4 CVE-2024-49105 Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client 1.2.5716.0 / 2.0.327.0+ Fix from $1,9502024-12-12 HIGH 7.3 CVE-2024-49107 WmsRepair Service Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20857 / 10.0.14393.7606+ Fix from $1,9502024-12-12 HIGH 8.2 CVE-2024-49068 Microsoft SharePoint Elevation of Privilege Vulnerability Sharepoint Server Mitigation only Fix from $1,9502024-12-12 HIGH 7.8 CVE-2024-43600 Microsoft Office Elevation of Privilege Vulnerability Office No fix yet Fix from $1,9502024-12-12 HIGH 7.3 CVE-2024-43594 Microsoft System Center Elevation of Privilege Vulnerability System Center 2019 10.19.10050.0 / 10.22.10118.0+ Fix from $1,9502024-12-12 HIGH 7.1 CVE-2024-49049 Visual Studio Code Remote Extension Elevation of Privilege Vulnerability Remote Ssh 0.115.1+ Fix from $1,9502024-11-12 MEDIUM 6.7 CVE-2024-49044 Visual Studio Elevation of Privilege Vulnerability Visual Studio 2022 17.6.21 / 17.8.16+ Fix from $1,6002024-11-12 HIGH 7.8 CVE-2024-43530 Windows Update Stack Elevation of Privilege Vulnerability Windows 10 21h2 10.0.19044.5131 / 10.0.19045.5131+ Fix from $1,9502024-11-12 MEDIUM 6.5 CVE-2024-38204 Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network. Azure Functions Patch available Fix from $1,6002024-10-15 HIGH 7.8 CVE-2024-43590 Visual C++ Redistributable Installer Elevation of Privilege Vulnerability Visual C\+\+ Redistributable 14.40.33816 / 15.9.67+ Fix from $1,9502024-10-08 HIGH 7.8 CVE-2024-43503 Microsoft SharePoint Elevation of Privilege Vulnerability Sharepoint Server Patch available Fix from $1,9502024-10-08 HIGH 7.4 CVE-2024-43456 Windows Remote Desktop Services Tampering Vulnerability Windows Server 2008 10.0.14393.7428 / 10.0.17763.6414+ Fix from $1,9502024-10-08 HIGH 7.8 CVE-2024-38016 Microsoft Office Visio Remote Code Execution Vulnerability 365 Apps Patch available Fix from $1,9502024-09-19 HIGH 7.8 CVE-2024-43492 Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability Autoupdate 4.72+ Fix from $1,9502024-09-10 HIGH 8.5 CVE-2024-43479 Microsoft Power Automate Desktop Remote Code Execution Vulnerability Power Automate 2.41.178.24249 / 2.42.331.24249+ Fix from $1,9502024-09-10