Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 11 24h2 MEDIUM 6.5
CVE-2025-53809

Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

Fix: 10.0.26100.6508+
Fix from $1,600 2025-09-09
Windows 11 22h2 HIGH 7.5
CVE-2025-53805

Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.

Fix: 10.0.20348.4106 / 10.0.22621.5909+
Fix from $1,950 2025-09-09
Windows 10 1809 HIGH 7.0
CVE-2025-53807

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized atta…

Fix: 10.0.17763.7792 / 10.0.19044.6332+
Fix from $1,950 2025-09-09
Windows 10 1507 MEDIUM 6.7
CVE-2025-53808

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege…

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,600 2025-09-09
Windows Server 2008 MEDIUM 6.5
CVE-2025-53806

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.8422 / 10.0.17763.7792+
Fix from $1,600 2025-09-09
Windows 10 1507 MEDIUM 5.5
CVE-2025-53804

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,600 2025-09-09
Windows 10 1607 HIGH 7.8
CVE-2025-53800

No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8422 / 10.0.17763.7792+
Fix from $1,950 2025-09-09
Windows 10 1507 HIGH 7.8
CVE-2025-53801

Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,950 2025-09-09
Windows 10 21h2 HIGH 7.0
CVE-2025-53802

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.6332 / 10.0.19045.6332+
Fix from $1,950 2025-09-09
365 Copilot MEDIUM 5.5
CVE-2025-53799

Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,600 2025-09-09
Windows 10 1507 MEDIUM 5.5
CVE-2025-53803

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21128 / 10.0.14393.8422+
Fix from $1,600 2025-09-09
Windows Server 2008 MEDIUM 6.5
CVE-2025-53796

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.8422 / 10.0.17763.7792+
Fix from $1,600 2025-09-09
Windows Server 2008 MEDIUM 6.5
CVE-2025-53797

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.8422 / 10.0.17763.7792+
Fix from $1,600 2025-09-09
Windows Server 2008 MEDIUM 6.5
CVE-2025-53798

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.8422 / 10.0.17763.7792+
Fix from $1,600 2025-09-09
Powershell HIGH 7.0
CVE-2025-49734

Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.

Fix: 7.4.12 / 7.5.3+
Fix from $1,950 2025-09-09
Azure Connected Machine Agent HIGH 7.8
CVE-2025-49692

Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.49+
Fix from $1,950 2025-09-09
Sql Server 2016 MEDIUM 5.3
CVE-2025-47997

Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose i…

Fix: 13.0.6470.1 / 13.0.7065.1+
Fix from $1,600 2025-09-09
Azure Ai Bot Service CRITICAL 9.0
CVE-2025-55244

Azure Bot Service Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-09-04
Xbox Gaming Services HIGH 7.5
CVE-2025-55242

Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $1,950 2025-09-04
Entra Id CRITICAL 10.0
CVE-2025-55241

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-09-04
Azure Networking CRITICAL 9.8
CVE-2025-54914

Azure Networking Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-09-04
Dynamics 365 HIGH 7.5
CVE-2025-55238

Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability

No fix yet
Fix from $1,950 2025-09-04
Windows 11 23h2 HIGH 7.8
CVE-2025-9491EPSS 69%

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary …

Mitigation only
Fix from $1,950 2025-08-26
Windows 10 1507 HIGH 7.8
CVE-2025-55230

Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-08-21
Windows Server 2012 HIGH 7.5
CVE-2025-55231

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to exe…

Fix: 10.0.14393.8416 / 10.0.17763.7783+
Fix from $1,950 2025-08-21
Windows 10 1507 MEDIUM 5.3
CVE-2025-55229

Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-08-21
Pc Manager CRITICAL 9.8
CVE-2025-53795

Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-08-21
Purview Data Governance CRITICAL 9.8
CVE-2025-53763

Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-08-21
Windows 10 1507 HIGH 7.8
CVE-2025-53789

Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-08-12
Azure Stack Hub HIGH 7.5
CVE-2025-53793

Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.

Fix: 1.2406.1.23 / 1.2408.1.50+
Fix from $1,950 2025-08-12