Vulnerability index

Browse CVEs

3,038 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Power Apps HIGH 7.5
CVE-2025-47733

Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network

Mitigation only
Fix from $1,950 2025-05-08
Azure Devops CRITICAL 9.8
CVE-2025-29813

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-05-08
Azure Storage Resource Provider CRITICAL 9.8
CVE-2025-29972

Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.

Mitigation only
Fix from $2,300 2025-05-08
Dataverse CRITICAL 9.8
CVE-2025-47732

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2025-05-08
Azure Automation HIGH 8.8
CVE-2025-29827

Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-05-08
Msagsfeedback.azurewebsites.net HIGH 7.5
CVE-2025-33072

Improper access control in Azure allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2025-05-08
Azure Functions HIGH 8.8
CVE-2025-33074

Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-04-30
Azure Ai Bot Service CRITICAL 9.8
CVE-2025-30389

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-04-30
Azure Ai Bot Service CRITICAL 9.8
CVE-2025-30392

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-04-30
Azure Machine Learning HIGH 8.8
CVE-2025-30390

Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2025-04-30
Dynamics 365 Customer Service HIGH 7.5
CVE-2025-30391

Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2025-04-30
Azure Virtual Desktop HIGH 8.8
CVE-2025-21416

Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-04-30
Office HIGH 7.8
CVE-2025-29822

Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-29823

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-29820

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.5
CVE-2025-29816

Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.

No fix yet
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-29791

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.3
CVE-2025-29792

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-27747

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-27748

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-27749

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-27750

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-27751

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-27752

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
System Center Data Protection Manager HIGH 7.8
CVE-2025-27743

Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2025-04-08
Office HIGH 7.8
CVE-2025-27744

Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-27745

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-26642

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
Azure Health Bot HIGH 8.8
CVE-2025-21384

An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a …

Mitigation only
Fix from $1,950 2025-04-01
Azure Playwright CRITICAL 9.8
CVE-2025-26683

Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-03-31