Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2025-59190 Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 HIGH 7.0 CVE-2025-58737 Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally. Windows Server 2012 10.0.17763.7919 / 10.0.20348.4294+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-58738 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Windows 10 1507 10.0.10240.21161 / 10.0.17763.7919+ Fix from $1,9502025-10-14 MEDIUM 6.5 CVE-2025-58739 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a networ… Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 MEDIUM 6.5 CVE-2025-59185 External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 MEDIUM 5.5 CVE-2025-59184 Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose informatio… Windows Server 2016 10.0.17763.7919 / 10.0.20348.4294+ Fix from $1,6002025-10-14 HIGH 7.0 CVE-2025-58731 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Windows 11 22h2 10.0.20348.4294 / 10.0.22621.6060+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-58732 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-58733 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-58734 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-58735 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-58736 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-58728 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7919 / 10.0.19044.6456+ Fix from $1,9502025-10-14 HIGH 7.5 CVE-2025-58726 Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-58727 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an a… Windows 10 21h2 10.0.19044.6456 / 10.0.19045.6456+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-58730 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 MEDIUM 6.5 CVE-2025-58729 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 HIGH 8.8 CVE-2025-58718 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Remote Desktop Client 1.2.6599 / 2.0.706.0+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-58720 Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information … Windows 10 1809 10.0.17763.7919 / 10.0.19044.6456+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-58722 Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8519 / 10.0.17763.7919+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-58724 Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. Azure Connected Machine Agent 1.57+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-58725 Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 8.8 CVE-2025-58715 Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 8.8 CVE-2025-58716 Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-55701 Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-58714 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-55697 Heap-based buffer overflow in Azure Local allows an authorized attacker to elevate privileges locally. Windows Server 2022 23h2 10.0.25398.1913 / 10.0.26100.6899+ Fix from $1,9502025-10-14 HIGH 7.7 CVE-2025-55698 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network. Windows 11 24h2 10.0.26100.6899 / 10.0.26200.6899+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-55696 Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges … Windows 10 1809 10.0.17763.7919 / 10.0.19044.6456+ Fix from $1,9502025-10-14 MEDIUM 5.5 CVE-2025-55699 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14