Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1607 HIGH 7.8
CVE-2025-48799

Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Windows 10 1507 MEDIUM 6.8
CVE-2025-48001

Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical a…

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,600 2025-07-08
Windows 10 1809 MEDIUM 6.8
CVE-2025-48003

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Fix: 10.0.17763.7558 / 10.0.19044.6093+
Fix from $1,600 2025-07-08
Windows 10 1507 MEDIUM 6.8
CVE-2025-48800

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,600 2025-07-08
Windows 11 24h2 MEDIUM 5.7
CVE-2025-48002

Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network.

Fix: 10.0.26100.4652+
Fix from $1,600 2025-07-08
Windows Server 2008 HIGH 8.8
CVE-2025-47998

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
365 Apps HIGH 8.6
CVE-2025-47994

Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-47996

Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1607 HIGH 7.8
CVE-2025-48000

Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Windows 10 1607 MEDIUM 6.8
CVE-2025-47999

Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,600 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-47987

Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1607 HIGH 7.8
CVE-2025-47991

Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Windows 11 24h2 HIGH 7.8
CVE-2025-47993

Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.25398.1732 / 10.0.26100.4652+
Fix from $1,950 2025-07-08
Azure Monitor Agent HIGH 7.5
CVE-2025-47988

Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent net…

Fix: 1.35.1+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 8.8
CVE-2025-47986

Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1607 HIGH 7.8
CVE-2025-47982

Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-47985

Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.5
CVE-2025-47984EPSS 16%

Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 CRITICAL 9.8
CVE-2025-47981EPSS 32%

Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $2,300 2025-07-08
Windows Server 2022 MEDIUM 6.5
CVE-2025-47978

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

Fix: 10.0.20348.3932 / 10.0.25398.1732+
Fix from $1,600 2025-07-08
Windows 10 1507 MEDIUM 6.2
CVE-2025-47980

Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information local…

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,600 2025-07-08
Windows 10 1507 HIGH 8.0
CVE-2025-47972

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authoriz…

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-47971

Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-47973

Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-47976

Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.0
CVE-2025-47975

Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Configuration Manager 2503 HIGH 8.0
CVE-2025-47178

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker…

Fix: 5.00.9135.1003+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-47159

Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 11 22h2 HIGH 8.1
CVE-2025-33054

Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.22621.5624 / 10.0.22631.5624+
Fix from $1,950 2025-07-08
Azure Service Fabric MEDIUM 6.0
CVE-2025-21195

Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.

Fix: 10.1+
Fix from $1,600 2025-07-08