Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1507 MEDIUM 6.2
CVE-2025-29957

Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows 10 1507 MEDIUM 5.9
CVE-2025-29954

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a netw…

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows 11 24h2 MEDIUM 5.5
CVE-2025-29955

Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.

Fix: 10.0.25398.1611 / 10.0.26100.4061+
Fix from $1,600 2025-05-13
Windows 10 1507 MEDIUM 5.4
CVE-2025-29956

Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows 10 1507 HIGH 8.8
CVE-2025-29840

Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Windows 11 24h2 HIGH 7.0
CVE-2025-29838

Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.26100.4061+
Fix from $1,950 2025-05-13
Windows 10 21h2 HIGH 7.0
CVE-2025-29841

Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorize…

Fix: 10.0.19044.5854 / 10.0.19045.5854+
Fix from $1,950 2025-05-13
Windows 10 1507 MEDIUM 6.5
CVE-2025-29836

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows 10 1507 MEDIUM 5.5
CVE-2025-29837

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows 10 1507 HIGH 7.7
CVE-2025-29833

Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Windows Server 2008 HIGH 7.5
CVE-2025-29831

Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8066 / 10.0.17763.7314+
Fix from $1,950 2025-05-13
Windows 10 1507 MEDIUM 6.5
CVE-2025-29830

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a netw…

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows 10 1507 MEDIUM 6.5
CVE-2025-29832

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows 10 1507 MEDIUM 6.5
CVE-2025-29835

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Dataverse HIGH 8.8
CVE-2025-29826

Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

Fix: 3.4.0.1406+
Fix from $1,950 2025-05-13
Windows 10 1507 HIGH 7.0
CVE-2025-27468

Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Windows Hardware Lab Kit MEDIUM 6.7
CVE-2025-27488

Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.

Fix: 10.1.17763.7010 / 10.1.19041.5609+
Fix from $1,600 2025-05-13
Defender For Identity MEDIUM 6.5
CVE-2025-26685

Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

Mitigation only
Fix from $1,600 2025-05-13
Windows 10 1507 MEDIUM 5.5
CVE-2025-29829

Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows 10 1507 HIGH 7.8
CVE-2025-24063

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Windows Server 2016 HIGH 7.5
CVE-2025-26677

Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.8066 / 10.0.17763.7314+
Fix from $1,950 2025-05-13
Visual Studio Code HIGH 7.1
CVE-2025-21264

Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Fix: 1.100.1+
Fix from $1,950 2025-05-13
Defender For Endpoint MEDIUM 6.7
CVE-2025-26684

External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

Fix: 101.25032.0008+
Fix from $1,600 2025-05-13
Power Apps HIGH 7.5
CVE-2025-47733

Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network

Mitigation only
Fix from $1,950 2025-05-08
Azure Devops CRITICAL 9.8
CVE-2025-29813

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-05-08
Azure Storage Resource Provider CRITICAL 9.8
CVE-2025-29972

Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.

Mitigation only
Fix from $2,300 2025-05-08
Dataverse CRITICAL 9.8
CVE-2025-47732

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2025-05-08
Azure Automation HIGH 8.8
CVE-2025-29827

Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-05-08
Msagsfeedback.azurewebsites.net HIGH 7.5
CVE-2025-33072

Improper access control in Azure allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2025-05-08
Edge Chromium MEDIUM 6.5
CVE-2025-29825

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing …

Fix: 136.0.3240.50+
Fix from $1,600 2025-05-02