Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Azure Monitor Agent HIGH 8.8
CVE-2025-62550

Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

Fix: 1.35.9+
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62552

Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62553

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62554

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62556

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20075+
Fix from $1,950 2025-12-09
365 Apps HIGH 7.0
CVE-2025-62555

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 8.8
CVE-2025-62549

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-62470

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-62472

Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-62474

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 11 24h2 HIGH 7.0
CVE-2025-62469

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized a…

Fix: 10.0.26100.7392 / 10.0.26200.7392+
Fix from $1,950 2025-12-09
Windows 10 1607 MEDIUM 6.5
CVE-2025-62473

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,600 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-62464

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-62466

Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-62467

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 10 21h2 MEDIUM 6.5
CVE-2025-62463

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

Fix: 10.0.19044.6691 / 10.0.19045.6691+
Fix from $1,600 2025-12-09
Windows 11 23h2 MEDIUM 6.5
CVE-2025-62465

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

Fix: 10.0.20348.4467 / 10.0.22631.6345+
Fix from $1,600 2025-12-09
Windows 11 23h2 MEDIUM 5.5
CVE-2025-62468

Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

Fix: 10.0.22631.6345 / 10.0.25398.2025+
Fix from $1,600 2025-12-09
Windows 11 23h2 HIGH 8.8
CVE-2025-62456

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.

Fix: 10.0.20348.4467 / 10.0.22631.6345+
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-62457

Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-62458

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-62461

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-62462

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-62221 KEV

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-62454

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-62455

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-55233

Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-59516

Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-59517

Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-54100

Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute …

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09