Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 21h2 HIGH 7.8
CVE-2025-27490

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.5737 / 10.0.19045.5737+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.5
CVE-2025-27484

Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate pri…

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows Server 2012 HIGH 7.5
CVE-2025-27485

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows Server 2012 HIGH 7.5
CVE-2025-27486

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 8.8
CVE-2025-27481

Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows Server 2012 HIGH 8.1
CVE-2025-27480EPSS 10%

Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows Server 2016 HIGH 8.1
CVE-2025-27482

Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.8
CVE-2025-27483

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows Server 2012 HIGH 7.5
CVE-2025-27479

Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.0
CVE-2025-27478

Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 8.8
CVE-2025-27477

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1809 HIGH 7.8
CVE-2025-27476

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.5
CVE-2025-27473

Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 11 22h2 HIGH 7.0
CVE-2025-27475

Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22621.5189 / 10.0.22631.5189+
Fix from $1,950 2025-04-08
Windows Server 2008 MEDIUM 6.5
CVE-2025-27474

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a netw…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,600 2025-04-08
Windows 10 1507 MEDIUM 5.4
CVE-2025-27472

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.10240.20978+
Fix from $1,600 2025-04-08
Windows 10 1809 HIGH 7.8
CVE-2025-27467

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.5
CVE-2025-27469

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a netw…

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows Server 2012 HIGH 7.5
CVE-2025-27470

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows 10 1507 MEDIUM 5.9
CVE-2025-27471

Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,600 2025-04-08
Windows 10 1507 HIGH 7.8
CVE-2025-26688

Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Asp.net Core HIGH 7.5
CVE-2025-26682

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Fix: 8.0.15 / 9.0.4+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.5
CVE-2025-26686

Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
365 Copilot HIGH 7.5
CVE-2025-26687

Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1809 HIGH 8.4
CVE-2025-26678

Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.8
CVE-2025-26679

Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows Server 2012 HIGH 7.5
CVE-2025-26680

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows 10 21h2 MEDIUM 6.7
CVE-2025-26681

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.5737 / 10.0.19045.5737+
Fix from $1,600 2025-04-08
Windows Server 2008 MEDIUM 6.5
CVE-2025-26676

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,600 2025-04-08
Windows Server 2008 HIGH 8.1
CVE-2025-26671

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08