Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2025-64677 Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker … Office Out Of Box Experience Mitigation only Fix from $1,9502025-12-18 HIGH 8.8 CVE-2025-64663 Custom Question Answering Elevation of Privilege Vulnerability Azure Language No fix yet Fix from $1,9502025-12-18 HIGH 7.2 CVE-2025-64676 '.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network. Purview No fix yet Fix from $1,9502025-12-18 HIGH 7.8 CVE-2025-64669 Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally. Windows Admin Center 2511+ Fix from $1,9502025-12-11 HIGH 7.8 CVE-2025-64679 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-64680 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-12-09 CRITICAL 9.0 CVE-2025-64672 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19127.20378+ Fix from $2,3002025-12-09 HIGH 8.8 CVE-2025-64678 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-64671 Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locall… Github Copilot 1.5.60-243+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-64673 Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8146 / 10.0.19044.6691+ Fix from $1,9502025-12-09 MEDIUM 6.5 CVE-2025-64670 Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over… Windows 10 21h2 10.0.19044.6691 / 10.0.19045.6691+ Fix from $1,6002025-12-09 MEDIUM 5.3 CVE-2025-64667 User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a… Exchange Server 15.02.2562.035+ Fix from $1,6002025-12-09 HIGH 7.8 CVE-2025-64661 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate… Windows 10 1607 10.0.14393.8688 / 10.0.17763.8146+ Fix from $1,9502025-12-09 HIGH 7.5 CVE-2025-64658 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate… Windows 10 1809 10.0.17763.8146 / 10.0.19044.6691+ Fix from $1,9502025-12-09 HIGH 7.5 CVE-2025-64666 Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Exchange Server 15.02.2562.035+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-62571 Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8688 / 10.0.17763.8146+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-62572 Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.7392 / 10.0.26200.7392+ Fix from $1,9502025-12-09 HIGH 7.0 CVE-2025-62569 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.25398.2025 / 10.0.26100.7392+ Fix from $1,9502025-12-09 HIGH 7.0 CVE-2025-62573 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8688 / 10.0.17763.8146+ Fix from $1,9502025-12-09 MEDIUM 5.5 CVE-2025-62570 Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally. Windows 11 24h2 10.0.26100.7392 / 10.0.26200.7392+ Fix from $1,6002025-12-09 HIGH 7.8 CVE-2025-62562 Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-62563 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20075+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-62564 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20075+ Fix from $1,9502025-12-09 HIGH 7.3 CVE-2025-62565 Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8688 / 10.0.17763.8146+ Fix from $1,9502025-12-09 MEDIUM 5.3 CVE-2025-62567 Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network. Windows 10 1607 10.0.14393.8688 / 10.0.17763.8146+ Fix from $1,6002025-12-09 HIGH 7.8 CVE-2025-62557 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-62558 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-62559 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-62560 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20075+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-62561 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20075+ Fix from $1,9502025-12-09