Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Office Out Of Box Experience HIGH 8.2
CVE-2025-64677

Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker …

Mitigation only
Fix from $1,950 2025-12-18
Azure Language HIGH 8.8
CVE-2025-64663

Custom Question Answering Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2025-12-18
Purview HIGH 7.2
CVE-2025-64676

'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2025-12-18
Windows Admin Center HIGH 7.8
CVE-2025-64669

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.

Fix: 2511+
Fix from $1,950 2025-12-11
Windows 10 1507 HIGH 7.8
CVE-2025-64679

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-12-09
Windows 10 1507 HIGH 7.8
CVE-2025-64680

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-12-09
Sharepoint Server CRITICAL 9.0
CVE-2025-64672

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19127.20378+
Fix from $2,300 2025-12-09
Windows 10 1607 HIGH 8.8
CVE-2025-64678

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-12-09
Github Copilot HIGH 7.8
CVE-2025-64671

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locall…

Fix: 1.5.60-243+
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-64673

Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 10 21h2 MEDIUM 6.5
CVE-2025-64670

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over…

Fix: 10.0.19044.6691 / 10.0.19045.6691+
Fix from $1,600 2025-12-09
Exchange Server MEDIUM 5.3
CVE-2025-64667

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a…

Fix: 15.02.2562.035+
Fix from $1,600 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-64661

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate…

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.5
CVE-2025-64658

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate…

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Exchange Server HIGH 7.5
CVE-2025-64666

Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Fix: 15.02.2562.035+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-62571

Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 11 24h2 HIGH 7.8
CVE-2025-62572

Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.7392 / 10.0.26200.7392+
Fix from $1,950 2025-12-09
Windows 11 24h2 HIGH 7.0
CVE-2025-62569

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.25398.2025 / 10.0.26100.7392+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.0
CVE-2025-62573

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 11 24h2 MEDIUM 5.5
CVE-2025-62570

Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.

Fix: 10.0.26100.7392 / 10.0.26200.7392+
Fix from $1,600 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62562

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62563

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20075+
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62564

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20075+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.3
CVE-2025-62565

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 10 1607 MEDIUM 5.3
CVE-2025-62567

Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,600 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62557

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62558

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62559

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62560

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20075+
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62561

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20075+
Fix from $1,950 2025-12-09