Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1809 HIGH 7.8
CVE-2025-24074

Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 8.8
CVE-2025-21205

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 8.8
CVE-2025-21221

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 8.8
CVE-2025-21222

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.8
CVE-2025-21204EPSS 7%

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1507 MEDIUM 6.5
CVE-2025-21197

Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't hav…

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,600 2025-04-08
Windows Server 2008 MEDIUM 6.5
CVE-2025-21203

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,600 2025-04-08
Windows Server 2012 HIGH 7.5
CVE-2025-21174

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.0
CVE-2025-21191

Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges local…

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Edge Chromium HIGH 7.6
CVE-2025-29815

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Fix: 134.0.3124.66+
Fix from $1,950 2025-04-04
Edge Chromium HIGH 8.8
CVE-2025-25000

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over…

Fix: 135.0.3179.54+
Fix from $1,950 2025-04-04
Azure Health Bot HIGH 8.8
CVE-2025-21384

An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a …

Mitigation only
Fix from $1,950 2025-04-01
Azure Playwright CRITICAL 9.8
CVE-2025-26683

Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-03-31
Edge Chromium MEDIUM 6.5
CVE-2025-29806

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 129.0.2792.52+
Fix from $1,600 2025-03-23
Edge Update HIGH 7.8
CVE-2025-29795

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges…

Fix: 1.3.195.45+
Fix from $1,950 2025-03-23
Dataverse HIGH 8.8
CVE-2025-29807

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-03-21
Partner Center HIGH 8.8
CVE-2025-29814

Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-03-21
Dataverse HIGH 7.2
CVE-2025-24053

Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-03-13
Windows 10 1507 HIGH 8.8
CVE-2025-26645

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.20947 / 10.0.14393.7876+
Fix from $1,950 2025-03-11
Windows 10 1507 HIGH 7.5
CVE-2025-26634

Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-03-11
Visual Studio Code HIGH 7.3
CVE-2025-26631

Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.

Fix: 1.98.0+
Fix from $1,950 2025-03-11
Windows 10 1507 HIGH 7.0
CVE-2025-26633 KEVEPSS 30%

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

Fix: 10.0.10240.20947 / 10.0.14393.7876+
Fix from $1,950 2025-03-11
365 Apps HIGH 7.8
CVE-2025-26630

Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
365 Apps HIGH 7.8
CVE-2025-26629

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-03-11
Visual Studio 2019 HIGH 7.3
CVE-2025-25003

Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.

Fix: 16.11.45 / 17.8.19+
Fix from $1,950 2025-03-11
Windows Server 2016 HIGH 7.1
CVE-2025-25008

Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.7876 / 10.0.17763.7009+
Fix from $1,950 2025-03-11
Azure Arc HIGH 7.0
CVE-2025-26627

Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges …

Fix: 1.0.10+
Fix from $1,950 2025-03-11
Visual Studio 2017 HIGH 7.3
CVE-2025-24998

Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.

Fix: 15.9.71 / 16.11.45+
Fix from $1,950 2025-03-11
Windows 10 1507 HIGH 7.8
CVE-2025-24995

Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.20947 / 10.0.14393.7876+
Fix from $1,950 2025-03-11
Windows 11 22h2 HIGH 7.3
CVE-2025-24994

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22621.5039 / 10.0.22631.5039+
Fix from $1,950 2025-03-11