Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Azure Application Gateway CRITICAL 9.8
CVE-2025-64656

Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-11-26
Azure Application Gateway CRITICAL 9.8
CVE-2025-64657

Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-11-26
Dynamics Omnichannel Sdk Storage Containers CRITICAL 9.8
CVE-2025-64655

Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-11-20
Visual Studio Code HIGH 8.0
CVE-2025-64660

Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.

Fix: 1.106.2+
Fix from $1,950 2025-11-20
365 Defender Portal MEDIUM 6.1
CVE-2025-62459

Microsoft Defender Portal Spoofing Vulnerability

No fix yet
Fix from $1,600 2025-11-20
Azure Monitor CRITICAL 9.8
CVE-2025-62207

Azure Monitor Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-11-20
Sharepoint Online CRITICAL 9.8
CVE-2025-59245

Microsoft SharePoint Online Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-11-20
Azure Bastion Developer CRITICAL 10.0
CVE-2025-49752

Azure Bastion Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-11-20
Windows 10 1607 HIGH 8.0
CVE-2025-62452

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Github Copilot Chat MEDIUM 6.8
CVE-2025-62449

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized atta…

Fix: 0.32.0+
Fix from $1,600 2025-11-11
Visual Studio Code MEDIUM 5.0
CVE-2025-62453

Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature local…

Fix: 1.105.0+
Fix from $1,600 2025-11-11
Windows Subsystem For Linux HIGH 8.8
CVE-2025-62220

Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network.

Fix: 2.6.2+
Fix from $1,950 2025-11-11
Github Copilot Chat HIGH 8.8
CVE-2025-62222

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthoriz…

Fix: 0.32.5+
Fix from $1,950 2025-11-11
365 Apps HIGH 7.8
CVE-2025-62216

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-62217

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a…

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-62218

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an autho…

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-62219

Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Dynamics 365 HIGH 8.7
CVE-2025-62210

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized atta…

Fix: 8.8.139.398+
Fix from $1,950 2025-11-11
Dynamics 365 HIGH 8.7
CVE-2025-62211

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized atta…

Fix: 8.8.139.398+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-62213

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1809 HIGH 7.0
CVE-2025-62215 KEVEPSS 6%

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevat…

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,950 2025-11-11
Visual Studio 2022 MEDIUM 6.7
CVE-2025-62214

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code lo…

Fix: 17.14.17+
Fix from $1,600 2025-11-11
Windows 10 1507 MEDIUM 5.5
CVE-2025-62209

Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-11-11
Dynamics 365 MEDIUM 6.5
CVE-2025-62206

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose inform…

Fix: 9.1.41.07+
Fix from $1,600 2025-11-11
Windows 10 1507 MEDIUM 5.5
CVE-2025-62208

Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-11-11
365 Apps HIGH 7.8
CVE-2025-62205

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-11-11
Sharepoint Server HIGH 8.0
CVE-2025-62204

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19127.20338+
Fix from $1,950 2025-11-11
365 Apps HIGH 7.8
CVE-2025-62199

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.19426.20044+
Fix from $1,950 2025-11-11
365 Apps HIGH 7.8
CVE-2025-62200

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20068+
Fix from $1,950 2025-11-11
365 Apps HIGH 7.8
CVE-2025-62201

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20068+
Fix from $1,950 2025-11-11