Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.0 CVE-2025-59506 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to eleva… Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 HIGH 7.0 CVE-2025-59507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevat… Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 HIGH 7.0 CVE-2025-59508 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevat… Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 MEDIUM 5.5 CVE-2025-59509 Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally. Windows 10 1809 10.0.17763.8027 / 10.0.19044.6575+ Fix from $1,6002025-11-11 MEDIUM 5.5 CVE-2025-59510 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to d… Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,6002025-11-11 HIGH 8.8 CVE-2025-59499 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6475.1 / 13.0.7070.1+ Fix from $1,9502025-11-11 HIGH 8.1 CVE-2025-30398 Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. Nuance Powerscribe 360 Mitigation only Fix from $1,9502025-11-11 HIGH 7.3 CVE-2025-59504 Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally. Azure Monitor Agent 1.37.1+ Fix from $1,9502025-11-11 MEDIUM 6.7 CVE-2025-47179 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. Configuration Manager 2403 5.00.9128.1037 / 5.00.9132.1031+ Fix from $1,6002025-11-11 MEDIUM 5.5 CVE-2025-59240 Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 365 Apps No fix yet Fix from $1,6002025-11-11 MEDIUM 6.3 CVE-2025-60711 Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 142.0.3595.53+ Fix from $1,6002025-10-31 CRITICAL 9.8 CVE-2025-59503 Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network. Azure Compute Resource Provider Mitigation only Fix from $2,3002025-10-23 HIGH 8.8 CVE-2025-59500 Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network. Azure Notification Service Mitigation only Fix from $1,9502025-10-23 CRITICAL 9.8 CVE-2025-59273 Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network. Azure Event Grid No fix yet Fix from $2,3002025-10-23 HIGH 7.5 CVE-2025-59502 Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network. Windows 10 1809 10.0.17763.7792 / 10.0.19044.6332+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59494 Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. Azure Monitor Agent 1.38.1+ Fix from $1,9502025-10-14 HIGH 8.8 CVE-2025-59295 Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 8.2 CVE-2025-59291 External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. Azure Compute Gallery Mitigation only Fix from $1,9502025-10-14 HIGH 8.2 CVE-2025-59292 External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. Azure Compute Gallery Mitigation only Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59290 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.6332 / 10.0.19045.6332+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-59289 Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.6332 / 10.0.19045.6332+ Fix from $1,9502025-10-14 CRITICAL 9.8 CVE-2025-59287 KEVEPSS 100% Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. Windows Server 2012 10.0.14393.8524 / 10.0.17763.7922+ Fix from $2,3002025-10-14 HIGH 7.0 CVE-2025-59282 Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to e… Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-59285 Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. Azure Monitor Agent 1.36.3+ Fix from $1,9502025-10-14 MEDIUM 5.5 CVE-2025-59284 Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally. Windows 11 22h2 10.0.22621.6060 / 10.0.22631.6060+ Fix from $1,6002025-10-14 MEDIUM 5.3 CVE-2025-59288 Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network. Playwright 1.55.1+ Fix from $1,6002025-10-14 HIGH 7.8 CVE-2025-59278 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59281 Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally. Xbox Gaming Services 31.105.17001.0+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59275 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59277 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14