Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows Subsystem For Linux HIGH 7.0
CVE-2025-53788

Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

Fix: 2.5.10+
Fix from $1,950 2025-08-12
Windows 10 1507 HIGH 8.8
CVE-2025-53778EPSS 38%

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
365 Apps HIGH 8.4
CVE-2025-53784

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
Dynamics 365 Guides HIGH 7.5
CVE-2025-53783

Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.

Fix: 1.0.0.2025102802 / 1.0.94.2025168802+
Fix from $1,950 2025-08-12
Windows Server 2025 HIGH 7.2
CVE-2025-53779

Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.26100.4851+
Fix from $1,950 2025-08-12
Ecesv6 Series Azure Vm Firmware MEDIUM 6.5
CVE-2025-53781

Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a net…

No fix yet
Fix from $1,600 2025-08-12
365 Copilot CRITICAL 9.8
CVE-2025-53766EPSS 7%

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $2,300 2025-08-12
Web Deploy 4.0 HIGH 8.8
CVE-2025-53772EPSS 22%

Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.

Fix: 10.0.2001+
Fix from $1,950 2025-08-12
365 Apps HIGH 7.8
CVE-2025-53761

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
Visual Studio 2022 HIGH 7.8
CVE-2025-53773

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attack…

Fix: 17.14.12+
Fix from $1,950 2025-08-12
Azure App Service On Azure Stack MEDIUM 5.5
CVE-2025-53765

Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.

Fix: 102.10.2.11+
Fix from $1,600 2025-08-12
Windows Security App MEDIUM 5.5
CVE-2025-53769

External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

Fix: 1000.27840.0.1000+
Fix from $1,600 2025-08-12
365 Apps HIGH 8.4
CVE-2025-53740

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
365 Apps HIGH 7.8
CVE-2025-53738

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
365 Apps HIGH 7.8
CVE-2025-53739

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
365 Apps HIGH 7.8
CVE-2025-53741

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
365 Apps HIGH 7.8
CVE-2025-53759

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
Sharepoint Server HIGH 7.1
CVE-2025-53760EPSS 12%

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Fix: 16.0.18526.20518+
Fix from $1,950 2025-08-12
365 Apps HIGH 8.4
CVE-2025-53733

Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
365 Copilot HIGH 7.8
CVE-2025-53732

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.14326.22618 / 16.0.19127.20000+
Fix from $1,950 2025-08-12
365 Apps HIGH 7.8
CVE-2025-53734

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
365 Apps HIGH 7.8
CVE-2025-53735

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
365 Apps HIGH 7.8
CVE-2025-53737

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
365 Apps MEDIUM 6.2
CVE-2025-53736

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Mitigation only
Fix from $1,600 2025-08-12
Sql Server 2016 HIGH 8.8
CVE-2025-53727

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6465.1 / 13.0.7060.1+
Fix from $1,950 2025-08-12
365 Apps HIGH 8.4
CVE-2025-53731

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
Windows 10 1507 HIGH 7.8
CVE-2025-53726

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges local…

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
Azure File Sync HIGH 7.8
CVE-2025-53729

Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.

Fix: 18.3.0.0 / 19.2.0.0+
Fix from $1,950 2025-08-12
365 Apps HIGH 7.8
CVE-2025-53730

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-08-12
Dynamics 365 MEDIUM 6.5
CVE-2025-53728

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose inform…

Fix: 9.1.39.04+
Fix from $1,600 2025-08-12