Vulnerability index

Browse CVEs

3,038 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-29807 Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. Dataverse Mitigation only Fix from $1,9502025-03-21 HIGH 8.8 CVE-2025-29814 Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. Partner Center Mitigation only Fix from $1,9502025-03-21 HIGH 7.2 CVE-2025-24053 Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. Dataverse Mitigation only Fix from $1,9502025-03-13 HIGH 7.8 CVE-2025-26630 Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-26629 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-24082 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-24083 Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-24081 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-24079 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-24080 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-24075 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-24077 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.0 CVE-2025-24078 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-24057 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-21194 Microsoft Surface Security Feature Bypass Vulnerability Surface Hub 2s Firmware No fix yet Fix from $1,9502025-02-11 HIGH 8.8 CVE-2025-21177 Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. Dynamics 365 Sales Mitigation only Fix from $1,9502025-02-06 MEDIUM 5.3 CVE-2025-21253 Microsoft Edge for IOS and Android Spoofing Vulnerability Edge No fix yet Fix from $1,6002025-02-06 HIGH 8.8 CVE-2025-21415 Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network. Azure Ai Face Service Mitigation only Fix from $1,9502025-01-29 HIGH 8.2 CVE-2025-21396 Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network. Account No fix yet Fix from $1,9502025-01-29 MEDIUM 6.5 CVE-2025-21380 Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network. Azure Marketplace No fix yet Fix from $1,6002025-01-09 MEDIUM 6.5 CVE-2025-21385EPSS 24% A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network. Purview No fix yet Fix from $1,6002025-01-09 CRITICAL 9.8 CVE-2024-42004 A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage… Teams No fix yet Fix from $2,3002024-12-18 CRITICAL 9.1 CVE-2024-41165 A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leadin… Word No fix yet Fix from $2,3002024-12-18 CRITICAL 9.1 CVE-2024-42220 A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges… Outlook No fix yet Fix from $2,3002024-12-18 CRITICAL 9.1 CVE-2024-43106 A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, lead… Excel No fix yet Fix from $2,3002024-12-18 HIGH 7.1 CVE-2024-41159 A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, … Onenote No fix yet Fix from $1,9502024-12-18 CRITICAL 9.8 CVE-2024-41138 A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.10… Teams No fix yet Fix from $2,3002024-12-18 CRITICAL 9.8 CVE-2024-41145 A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A speciall… Teams No fix yet Fix from $2,3002024-12-18 CRITICAL 9.1 CVE-2024-39804 A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privil… Powerpoint No fix yet Fix from $2,3002024-12-18 HIGH 7.5 CVE-2022-40732 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 ve… Windows 11 21h2 No fix yet Fix from $1,9502024-12-18