Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

.net HIGH 7.3
CVE-2025-55247

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.

Fix: 8.0.21 / 9.0.10+
Fix from $1,950 2025-10-14
.net Framework MEDIUM 5.7
CVE-2025-55248

Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

Fix: 8.0.21 / 9.0.10+
Fix from $1,600 2025-10-14
Windows 10 1809 HIGH 7.8
CVE-2025-50175

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7919 / 10.0.19044.6456+
Fix from $1,950 2025-10-14
Windows 10 1809 HIGH 7.8
CVE-2025-53150

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7919 / 10.0.19044.6456+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-53768

Use after free in Xbox allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 21h2 HIGH 7.1
CVE-2025-53139

Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.

Fix: 10.0.19044.6456 / 10.0.19045.6456+
Fix from $1,950 2025-10-14
Windows 11 24h2 HIGH 7.0
CVE-2025-50174

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.6899 / 10.0.26200.6899+
Fix from $1,950 2025-10-14
Windows 11 22h2 HIGH 7.0
CVE-2025-53717

Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate p…

Fix: 10.0.22621.6060 / 10.0.26100.6899+
Fix from $1,950 2025-10-14
Windows 10 1809 CRITICAL 9.9
CVE-2025-49708

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.17763.7919 / 10.0.19044.6456+
Fix from $2,300 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-50152

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Azure Connected Machine Agent HIGH 7.0
CVE-2025-47989

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.57+
Fix from $1,950 2025-10-14
Windows 11 22h2 HIGH 7.0
CVE-2025-48004

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.22621.6060 / 10.0.25398.1913+
Fix from $1,950 2025-10-14
Windows Server 2022 23h2 MEDIUM 5.5
CVE-2025-47979

Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.

Fix: 10.0.25398.1913+
Fix from $1,600 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-24990 KEVEPSS 6%

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an…

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Powershell HIGH 7.3
CVE-2025-25004

Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

Fix: 7.4.13 / 7.5.4+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-24052

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an…

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
365 Copilot Chat CRITICAL 9.3
CVE-2025-59286

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio…

Mitigation only
Fix from $2,300 2025-10-09
Entra Id CRITICAL 9.8
CVE-2025-59246EPSS 7%

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-10-09
Azure Playfab CRITICAL 9.8
CVE-2025-59247

Azure PlayFab Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-10-09
Entra Id CRITICAL 9.6
CVE-2025-59218

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-10-09
365 Word Copilot CRITICAL 9.3
CVE-2025-59252

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio…

Mitigation only
Fix from $2,300 2025-10-09
365 Copilot Chat CRITICAL 9.3
CVE-2025-59272

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information…

Mitigation only
Fix from $2,300 2025-10-09
Azure Cache For Redis HIGH 8.7
CVE-2025-59271

Redis Enterprise Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2025-10-09
Azure Monitor CRITICAL 9.3
CVE-2025-55321

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoo…

Mitigation only
Fix from $2,300 2025-10-09
Edge Chromium HIGH 7.6
CVE-2025-59251

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 140.0.3485.81+
Fix from $1,950 2025-09-24
Omniparser HIGH 7.3
CVE-2025-55322

Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.

Fix: 2.0.1+
Fix from $1,950 2025-09-24
Windows 10 21h2 HIGH 7.0
CVE-2025-59220

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacke…

Fix: 10.0.19044.6332 / 10.0.19045.6332+
Fix from $1,950 2025-09-18
Windows 11 24h2 HIGH 7.0
CVE-2025-59215

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.6508+
Fix from $1,950 2025-09-18
Windows 11 24h2 HIGH 7.0
CVE-2025-59216

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized atta…

Fix: 10.0.26100.6508+
Fix from $1,950 2025-09-18
Visual Studio Code CRITICAL 9.8
CVE-2025-55319

Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.

Fix: 1.104.0+
Fix from $2,300 2025-09-12