Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.0 CVE-2025-59261 Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.20348.4294 / 10.0.22621.6060+ Fix from $1,9502025-10-14 MEDIUM 6.5 CVE-2025-59257 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. Windows 11 24h2 10.0.25398.1913 / 10.0.26100.6899+ Fix from $1,6002025-10-14 MEDIUM 6.5 CVE-2025-59259 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 MEDIUM 6.2 CVE-2025-59258 Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information loca… Windows Server 2012 10.0.17763.7919 / 10.0.20348.4294+ Fix from $1,6002025-10-14 MEDIUM 5.5 CVE-2025-59260 Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose inf… Windows Server 2016 10.0.17763.7919 / 10.0.20348.4294+ Fix from $1,6002025-10-14 HIGH 8.8 CVE-2025-59249 Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. Exchange Server 15.02.2562.029+ Fix from $1,9502025-10-14 HIGH 8.1 CVE-2025-59250 Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network. Jdbc Driver For Sql Server 10.2.4 / 11.2.4+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59254 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59255 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7919 / 10.0.19044.6456+ Fix from $1,9502025-10-14 MEDIUM 5.5 CVE-2025-59253 Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 HIGH 7.8 CVE-2025-59241 Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allows an authorized attacker to e… Windows 11 24h2 10.0.26100.6899 / 10.0.26200.6899+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59242 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59243 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-10-14 HIGH 7.5 CVE-2025-59248 Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. Exchange Server 15.02.2562.029+ Fix from $1,9502025-10-14 MEDIUM 6.5 CVE-2025-59244 External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 HIGH 8.8 CVE-2025-59237 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20262+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59234 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19328.20000+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59236 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20059+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59238 Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-10-14 HIGH 7.1 CVE-2025-59235 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 365 Apps 16.0.10417.20059+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59230 KEV Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59231 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20059+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59233 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20059+ Fix from $1,9502025-10-14 HIGH 7.1 CVE-2025-59232 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 365 Apps 16.0.10417.20059+ Fix from $1,9502025-10-14 HIGH 8.8 CVE-2025-59228 Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20262+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59225 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20059+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59226 Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59227 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19328.20000+ Fix from $1,9502025-10-14 MEDIUM 5.5 CVE-2025-59229 Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally. 365 Apps No fix yet Fix from $1,6002025-10-14 HIGH 7.8 CVE-2025-59222 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-10-14