Vulnerability index

Browse CVEs

3,038 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dataverse HIGH 8.8
CVE-2025-29807

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-03-21
Partner Center HIGH 8.8
CVE-2025-29814

Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-03-21
Dataverse HIGH 7.2
CVE-2025-24053

Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-03-13
365 Apps HIGH 7.8
CVE-2025-26630

Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
365 Apps HIGH 7.8
CVE-2025-26629

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
365 Apps HIGH 7.8
CVE-2025-24082

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
365 Apps HIGH 7.8
CVE-2025-24083

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
365 Apps HIGH 7.8
CVE-2025-24081

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
365 Apps HIGH 7.8
CVE-2025-24079

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
365 Apps HIGH 7.8
CVE-2025-24080

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
365 Apps HIGH 7.8
CVE-2025-24075

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
365 Apps HIGH 7.8
CVE-2025-24077

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
365 Apps HIGH 7.0
CVE-2025-24078

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
365 Apps HIGH 7.8
CVE-2025-24057

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
Surface Hub 2s Firmware HIGH 7.1
CVE-2025-21194

Microsoft Surface Security Feature Bypass Vulnerability

No fix yet
Fix from $1,950 2025-02-11
Dynamics 365 Sales HIGH 8.8
CVE-2025-21177

Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-02-06
Edge MEDIUM 5.3
CVE-2025-21253

Microsoft Edge for IOS and Android Spoofing Vulnerability

No fix yet
Fix from $1,600 2025-02-06
Azure Ai Face Service HIGH 8.8
CVE-2025-21415

Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-01-29
Account HIGH 8.2
CVE-2025-21396

Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2025-01-29
Azure Marketplace MEDIUM 6.5
CVE-2025-21380

Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $1,600 2025-01-09
Purview MEDIUM 6.5
CVE-2025-21385EPSS 24%

A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $1,600 2025-01-09
Teams CRITICAL 9.8
CVE-2024-42004

A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage…

No fix yet
Fix from $2,300 2024-12-18
Word CRITICAL 9.1
CVE-2024-41165

A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leadin…

No fix yet
Fix from $2,300 2024-12-18
Outlook CRITICAL 9.1
CVE-2024-42220

A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges…

No fix yet
Fix from $2,300 2024-12-18
Excel CRITICAL 9.1
CVE-2024-43106

A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, lead…

No fix yet
Fix from $2,300 2024-12-18
Onenote HIGH 7.1
CVE-2024-41159

A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, …

No fix yet
Fix from $1,950 2024-12-18
Teams CRITICAL 9.8
CVE-2024-41138

A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.10…

No fix yet
Fix from $2,300 2024-12-18
Teams CRITICAL 9.8
CVE-2024-41145

A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A speciall…

No fix yet
Fix from $2,300 2024-12-18
Powerpoint CRITICAL 9.1
CVE-2024-39804

A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privil…

No fix yet
Fix from $2,300 2024-12-18
Windows 11 21h2 HIGH 7.5
CVE-2022-40732

An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 ve…

No fix yet
Fix from $1,950 2024-12-18