Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

365 Apps HIGH 7.8
CVE-2025-62203

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20068+
Fix from $1,950 2025-11-11
365 Apps HIGH 7.1
CVE-2025-62202

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Fix: 16.0.10417.20068+
Fix from $1,950 2025-11-11
365 Copilot CRITICAL 9.8
CVE-2025-60724EPSS 6%

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $2,300 2025-11-11
365 Apps HIGH 7.8
CVE-2025-60727

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20068+
Fix from $1,950 2025-11-11
365 Apps HIGH 7.1
CVE-2025-60726

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Fix: 16.0.10417.20068+
Fix from $1,950 2025-11-11
Windows 11 24h2 HIGH 7.8
CVE-2025-60718

Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.7092 / 10.0.26200.7092+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.8
CVE-2025-60720

Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 11 24h2 HIGH 7.8
CVE-2025-60721

Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.7092 / 10.0.26200.7092+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-60719

Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Onedrive MEDIUM 6.5
CVE-2025-60722

Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privi…

Fix: 7.42+
Fix from $1,600 2025-11-11
Windows 10 1809 MEDIUM 6.3
CVE-2025-60723

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny …

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,600 2025-11-11
Windows 10 1607 HIGH 8.0
CVE-2025-60715

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 11 24h2 HIGH 7.8
CVE-2025-60710 KEV

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges …

Fix: 10.0.26100.7392 / 10.0.26200.7392+
Fix from $1,950 2025-11-11
Windows Server 2016 HIGH 7.8
CVE-2025-60713

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.8
CVE-2025-60714

Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1809 HIGH 7.0
CVE-2025-60716

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,950 2025-11-11
Windows 10 1809 HIGH 7.0
CVE-2025-60717

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.8
CVE-2025-60705

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1809 HIGH 7.8
CVE-2025-60707

Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.8
CVE-2025-60709

Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.5
CVE-2025-60704

Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 MEDIUM 6.5
CVE-2025-60708

Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,600 2025-11-11
Windows 10 1607 MEDIUM 5.5
CVE-2025-60706

Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,600 2025-11-11
Windows 10 1809 HIGH 7.8
CVE-2025-59511

External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.8
CVE-2025-59512

Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.8
CVE-2025-59514

Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.8
CVE-2025-60703

Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1809 HIGH 7.0
CVE-2025-59515

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,950 2025-11-11
Windows 10 1607 MEDIUM 5.5
CVE-2025-59513

Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,600 2025-11-11
Windows 10 1607 HIGH 7.8
CVE-2025-59505

Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11