Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Visual Studio HIGH 8.8
CVE-2025-49739

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

Fix: 15.9.75 / 16.11.49+
Fix from $1,950 2025-07-08
Windows Server 2012 HIGH 8.1
CVE-2025-49735

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8148 / 10.0.17763.7434+
Fix from $1,950 2025-07-08
Windows 10 1809 HIGH 7.8
CVE-2025-49733

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7558 / 10.0.19044.6093+
Fix from $1,950 2025-07-08
Pc Manager HIGH 7.8
CVE-2025-49738

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.17.4.0+
Fix from $1,950 2025-07-08
Teams HIGH 7.0
CVE-2025-49737

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to eleva…

Fix: 25163.3001.3726.6503+
Fix from $1,950 2025-07-08
Windows Server 2008 HIGH 8.8
CVE-2025-49729

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-49730

Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-49732

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1809 HIGH 8.8
CVE-2025-49723

Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.

Fix: 10.0.17763.7558 / 10.0.19044.6093+
Fix from $1,950 2025-07-08
Windows 10 1809 HIGH 8.8
CVE-2025-49724EPSS 8%

Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.17763.7558 / 10.0.19044.6093+
Fix from $1,950 2025-07-08
Windows 10 1607 HIGH 7.8
CVE-2025-49725

Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Windows 10 1607 HIGH 7.8
CVE-2025-49726

Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.0
CVE-2025-49727

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Sql Server 2019 HIGH 8.5
CVE-2025-49717

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Fix: 15.0.2135.5 / 15.0.4435.7+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-49721

Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Sql Server 2019 HIGH 7.5
CVE-2025-49718

Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.

Fix: 15.0.2135.5 / 15.0.4435.7+
Fix from $1,950 2025-07-08
Sql Server 2016 HIGH 7.5
CVE-2025-49719EPSS 11%

Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.

Fix: 13.0.6460.7 / 13.0.7055.9+
Fix from $1,950 2025-07-08
Windows 10 1507 MEDIUM 5.7
CVE-2025-49722

Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,600 2025-07-08
365 Apps HIGH 7.8
CVE-2025-49705

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-07-08
365 Apps HIGH 7.8
CVE-2025-49711

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20027+
Fix from $1,950 2025-07-08
Python HIGH 7.8
CVE-2025-49714

Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally.

Fix: 2025.8.1+
Fix from $1,950 2025-07-08
Windows Server 2008 HIGH 7.5
CVE-2025-49716

Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Sharepoint Enterprise Server MEDIUM 6.5
CVE-2025-49706 KEVEPSS 100%

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Fix: 16.0.18526.20424+
Fix from $1,600 2025-07-08
Sharepoint Server HIGH 8.8
CVE-2025-49701

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.18526.20424+
Fix from $1,950 2025-07-08
Sharepoint Server HIGH 8.8
CVE-2025-49704 KEVEPSS 100%

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-07-08
365 Apps HIGH 7.8
CVE-2025-49702

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-07-08
365 Apps HIGH 7.8
CVE-2025-49703

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-07-08
365 Apps HIGH 8.4
CVE-2025-49697

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20027+
Fix from $1,950 2025-07-08
365 Apps HIGH 7.8
CVE-2025-49698

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-07-08
365 Apps HIGH 7.8
CVE-2025-49700

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-07-08