Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sharepoint Server HIGH 7.0
CVE-2025-30384

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

Fix: 16.0.18526.20286+
Fix from $1,950 2025-05-13
365 Apps HIGH 7.8
CVE-2025-30376

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20010+
Fix from $1,950 2025-05-13
365 Apps HIGH 7.8
CVE-2025-30377

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20010+
Fix from $1,950 2025-05-13
365 Apps HIGH 7.8
CVE-2025-30379

Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20010+
Fix from $1,950 2025-05-13
365 Apps HIGH 7.8
CVE-2025-30381

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20010+
Fix from $1,950 2025-05-13
Sharepoint Server HIGH 7.8
CVE-2025-30382

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

Fix: 16.0.18526.20286+
Fix from $1,950 2025-05-13
365 Apps HIGH 7.8
CVE-2025-30383

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20010+
Fix from $1,950 2025-05-13
Sharepoint Server HIGH 7.0
CVE-2025-30378

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

Fix: 16.0.18526.20286+
Fix from $1,950 2025-05-13
365 Apps HIGH 7.8
CVE-2025-29979

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20010+
Fix from $1,950 2025-05-13
365 Apps HIGH 7.8
CVE-2025-30375

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20010+
Fix from $1,950 2025-05-13
Pc Manager HIGH 7.8
CVE-2025-29975

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.16.1.0+
Fix from $1,950 2025-05-13
Sharepoint Server HIGH 7.8
CVE-2025-29976

Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.

Fix: 16.0.18526.20286+
Fix from $1,950 2025-05-13
365 Apps HIGH 7.8
CVE-2025-29977

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20010+
Fix from $1,950 2025-05-13
365 Apps HIGH 7.8
CVE-2025-29978

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-05-13
Azure File Sync HIGH 7.0
CVE-2025-29973

Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2025-05-13
Windows 10 1507 MEDIUM 5.7
CVE-2025-29974

Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Remote Desktop HIGH 8.8
CVE-2025-29966

Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.

Fix: 1.2.6228.0 / 2.0.420+
Fix from $1,950 2025-05-13
Windows 10 1507 HIGH 8.8
CVE-2025-29967

Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Windows 11 24h2 HIGH 7.8
CVE-2025-29970

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.25398.1611 / 10.0.26100.4061+
Fix from $1,950 2025-05-13
Windows 10 1507 HIGH 7.5
CVE-2025-29969

Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Windows 11 22h2 HIGH 7.5
CVE-2025-29971EPSS 64%

Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network.

Fix: 10.0.22621.5335 / 10.0.22631.5335+
Fix from $1,950 2025-05-13
Windows Server 2008 MEDIUM 6.5
CVE-2025-29968

Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.

Fix: 10.0.14393.8066 / 10.0.17763.7314+
Fix from $1,600 2025-05-13
Windows 10 1507 HIGH 8.8
CVE-2025-29962EPSS 14%

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Windows 10 1809 HIGH 8.8
CVE-2025-29963

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

Fix: 10.0.17763.7314 / 10.0.19044.5854+
Fix from $1,950 2025-05-13
Windows 10 1809 HIGH 8.8
CVE-2025-29964

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

Fix: 10.0.17763.7314 / 10.0.19044.5854+
Fix from $1,950 2025-05-13
Windows 10 1507 MEDIUM 6.5
CVE-2025-29959

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a netw…

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows 10 1507 MEDIUM 6.5
CVE-2025-29960

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows 10 1507 MEDIUM 6.5
CVE-2025-29961

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows 10 1507 HIGH 7.5
CVE-2025-29842

Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Windows 10 1507 MEDIUM 6.5
CVE-2025-29958

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a netw…

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13