Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Azure Functions HIGH 8.8
CVE-2025-33074

Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-04-30
Azure Ai Bot Service CRITICAL 9.8
CVE-2025-30389

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-04-30
Azure Ai Bot Service CRITICAL 9.8
CVE-2025-30392

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-04-30
Azure Machine Learning HIGH 8.8
CVE-2025-30390

Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2025-04-30
Dynamics 365 Customer Service HIGH 7.5
CVE-2025-30391

Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2025-04-30
Azure Virtual Desktop HIGH 8.8
CVE-2025-21416

Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-04-30
Power Automate For Desktop MEDIUM 5.7
CVE-2025-29817

Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.

Fix: 2.51.349.24355+
Fix from $1,600 2025-04-15
Edge Chromium HIGH 7.5
CVE-2025-29834

Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 134.0.3124.93+
Fix from $1,950 2025-04-12
Visual Studio Code MEDIUM 6.8
CVE-2025-32726

Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.

Fix: 1.99.1+
Fix from $1,600 2025-04-12
Sql Server Management Studio HIGH 7.3
CVE-2025-29803

Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate pr…

Fix: 16.0.35907.0 / 17.0.35906.0+
Fix from $1,950 2025-04-12
Office HIGH 7.8
CVE-2025-29822

Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-29823

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.8
CVE-2025-29824 KEVEPSS 14%

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 11 22h2 HIGH 7.8
CVE-2025-29812

Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

Fix: 10.0.20348.3453 / 10.0.22621.5189+
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-29820

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
365 Apps HIGH 7.5
CVE-2025-29816

Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.

No fix yet
Fix from $1,950 2025-04-08
Windows Admin Center MEDIUM 6.2
CVE-2025-29819

External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.

Fix: 0.45.0.0 / 2410+
Fix from $1,600 2025-04-08
Dynamics 365 Business Central 2023 MEDIUM 5.5
CVE-2025-29821

Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.

Fix: 23.18.32409 / 24.12.32447+
Fix from $1,600 2025-04-08
Windows 11 22h2 HIGH 7.8
CVE-2025-29811

Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22621.5189 / 10.0.22631.5189+
Fix from $1,950 2025-04-08
Outlook HIGH 7.5
CVE-2025-29805

Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a netw…

Fix: 4.2509.0+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.5
CVE-2025-29810

Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Visual Studio 2022 HIGH 7.3
CVE-2025-29802

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Fix: 17.8.20 / 17.10.13+
Fix from $1,950 2025-04-08
Visual Studio 2022 HIGH 7.3
CVE-2025-29804

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Fix: 17.8.20 / 17.10.13+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.1
CVE-2025-29809

Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows Server 2022 MEDIUM 5.5
CVE-2025-29808

Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information …

Fix: 10.0.20348.3453+
Fix from $1,600 2025-04-08
Sharepoint Enterprise Server HIGH 8.8
CVE-2025-29794

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.18526.20172+
Fix from $1,950 2025-04-08
365 Apps HIGH 7.8
CVE-2025-29791

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-04-08
Autoupdate HIGH 7.8
CVE-2025-29800

Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

Fix: 4.78+
Fix from $1,950 2025-04-08
Autoupdate HIGH 7.8
CVE-2025-29801

Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

Fix: 4.78+
Fix from $1,950 2025-04-08
365 Apps HIGH 7.3
CVE-2025-29792

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2025-04-08