Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1607 HIGH 7.0
CVE-2025-59506

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to eleva…

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-59507

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevat…

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-59508

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevat…

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1809 MEDIUM 5.5
CVE-2025-59509

Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,600 2025-11-11
Windows 10 1607 MEDIUM 5.5
CVE-2025-59510

Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to d…

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,600 2025-11-11
Sql Server 2016 HIGH 8.8
CVE-2025-59499

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6475.1 / 13.0.7070.1+
Fix from $1,950 2025-11-11
Nuance Powerscribe 360 HIGH 8.1
CVE-2025-30398

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2025-11-11
Azure Monitor Agent HIGH 7.3
CVE-2025-59504

Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

Fix: 1.37.1+
Fix from $1,950 2025-11-11
Configuration Manager 2403 MEDIUM 6.7
CVE-2025-47179

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.

Fix: 5.00.9128.1037 / 5.00.9132.1031+
Fix from $1,600 2025-11-11
365 Apps MEDIUM 5.5
CVE-2025-59240

Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $1,600 2025-11-11
Edge Chromium MEDIUM 6.3
CVE-2025-60711

Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 142.0.3595.53+
Fix from $1,600 2025-10-31
Azure Compute Resource Provider CRITICAL 9.8
CVE-2025-59503

Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-10-23
Azure Notification Service HIGH 8.8
CVE-2025-59500

Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-10-23
Azure Event Grid CRITICAL 9.8
CVE-2025-59273

Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-10-23
Windows 10 1809 HIGH 7.5
CVE-2025-59502

Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.

Fix: 10.0.17763.7792 / 10.0.19044.6332+
Fix from $1,950 2025-10-14
Azure Monitor Agent HIGH 7.8
CVE-2025-59494

Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.38.1+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 8.8
CVE-2025-59295

Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Azure Compute Gallery HIGH 8.2
CVE-2025-59291

External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2025-10-14
Azure Compute Gallery HIGH 8.2
CVE-2025-59292

External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2025-10-14
Windows 10 21h2 HIGH 7.8
CVE-2025-59290

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.6332 / 10.0.19045.6332+
Fix from $1,950 2025-10-14
Windows 10 21h2 HIGH 7.0
CVE-2025-59289

Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.6332 / 10.0.19045.6332+
Fix from $1,950 2025-10-14
Windows Server 2012 CRITICAL 9.8
CVE-2025-59287 KEVEPSS 100%

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8524 / 10.0.17763.7922+
Fix from $2,300 2025-10-14
Windows 10 1507 HIGH 7.0
CVE-2025-59282

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to e…

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Azure Monitor Agent HIGH 7.0
CVE-2025-59285

Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.36.3+
Fix from $1,950 2025-10-14
Windows 11 22h2 MEDIUM 5.5
CVE-2025-59284

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

Fix: 10.0.22621.6060 / 10.0.22631.6060+
Fix from $1,600 2025-10-14
Playwright MEDIUM 5.3
CVE-2025-59288

Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.

Fix: 1.55.1+
Fix from $1,600 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-59278

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Xbox Gaming Services HIGH 7.8
CVE-2025-59281

Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

Fix: 31.105.17001.0+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-59275

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-59277

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14