Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 11 24h2 MEDIUM 5.5
CVE-2025-26636

Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information loca…

Fix: 10.0.26100.4652+
Fix from $1,600 2025-07-08
Edge Chromium HIGH 8.8
CVE-2025-49713

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over…

Fix: 138.0.3351.65+
Fix from $1,950 2025-07-02
Edge Chromium HIGH 7.5
CVE-2025-49741

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Fix: 135.0.3179.98+
Fix from $1,950 2025-07-01
Dynamics 365 HIGH 7.5
CVE-2025-49715

Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to …

Mitigation only
Fix from $1,950 2025-06-20
Visual Studio 2022 HIGH 7.1
CVE-2025-47959EPSS 7%

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code ov…

Fix: 17.8.22 / 17.10.16+
Fix from $1,950 2025-06-13
Visual Studio 2022 HIGH 7.5
CVE-2025-30399

Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.

Fix: 7.4.11 / 7.5.2+
Fix from $1,950 2025-06-13
365 Copilot HIGH 7.5
CVE-2025-32711EPSS 8%

Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $1,950 2025-06-11
365 Apps HIGH 8.4
CVE-2025-32717

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-06-11
Nuance Digital Engagement Platform HIGH 8.2
CVE-2025-47977

Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized att…

Fix: 5.64.x+
Fix from $1,950 2025-06-10
Autoupdate HIGH 7.8
CVE-2025-47968

Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

Fix: 4.79+
Fix from $1,950 2025-06-10
Windows Software Development Kit HIGH 7.8
CVE-2025-47962

Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.4188+
Fix from $1,950 2025-06-10
365 Apps HIGH 8.4
CVE-2025-47957

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-06-10
Windows Security App MEDIUM 5.5
CVE-2025-47956

External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

Fix: 1000.27840.0.1000+
Fix from $1,600 2025-06-10
Windows 10 1507 HIGH 7.8
CVE-2025-47955

Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-06-10
365 Apps HIGH 8.4
CVE-2025-47953

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-06-10
365 Apps HIGH 7.8
CVE-2025-47176

'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.

No fix yet
Fix from $1,950 2025-06-10
365 Apps HIGH 7.8
CVE-2025-47175

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-06-10
365 Apps HIGH 7.8
CVE-2025-47174

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-06-10
365 Apps HIGH 7.8
CVE-2025-47173

Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-06-10
Sharepoint Enterprise Server HIGH 8.8
CVE-2025-47172

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: after 16.0.18526.20396
Fix from $1,950 2025-06-10
365 Apps MEDIUM 6.7
CVE-2025-47171

Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.

Mitigation only
Fix from $1,600 2025-06-10
365 Apps HIGH 7.8
CVE-2025-47170

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-06-10
365 Apps HIGH 7.8
CVE-2025-47169

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-06-10
365 Apps HIGH 7.8
CVE-2025-47168

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-06-10
365 Apps HIGH 8.4
CVE-2025-47167

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.18925.20000+
Fix from $1,950 2025-06-10
Sharepoint Enterprise Server HIGH 8.8
CVE-2025-47166EPSS 15%

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.18526.20396+
Fix from $1,950 2025-06-10
365 Apps HIGH 7.8
CVE-2025-47165

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20018+
Fix from $1,950 2025-06-10
365 Apps HIGH 8.4
CVE-2025-47164

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2025-06-10
Sharepoint Enterprise Server HIGH 8.8
CVE-2025-47163EPSS 15%

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.18526.20396+
Fix from $1,950 2025-06-10
365 Apps HIGH 8.4
CVE-2025-47162

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2025-06-10