Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2025-55247 Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally. .net 8.0.21 / 9.0.10+ Fix from $1,9502025-10-14 MEDIUM 5.7 CVE-2025-55248 Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. .net Framework 8.0.21 / 9.0.10+ Fix from $1,6002025-10-14 HIGH 7.8 CVE-2025-50175 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7919 / 10.0.19044.6456+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-53150 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7919 / 10.0.19044.6456+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-53768 Use after free in Xbox allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.1 CVE-2025-53139 Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally. Windows 10 21h2 10.0.19044.6456 / 10.0.19045.6456+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-50174 Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.6899 / 10.0.26200.6899+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-53717 Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate p… Windows 11 22h2 10.0.22621.6060 / 10.0.26100.6899+ Fix from $1,9502025-10-14 CRITICAL 9.9 CVE-2025-49708 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. Windows 10 1809 10.0.17763.7919 / 10.0.19044.6456+ Fix from $2,3002025-10-14 HIGH 7.8 CVE-2025-50152 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-47989 Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. Azure Connected Machine Agent 1.57+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-48004 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.6060 / 10.0.25398.1913+ Fix from $1,9502025-10-14 MEDIUM 5.5 CVE-2025-47979 Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally. Windows Server 2022 23h2 10.0.25398.1913+ Fix from $1,6002025-10-14 HIGH 7.8 CVE-2025-24990 KEVEPSS 6% Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an… Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.3 CVE-2025-25004 Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. Powershell 7.4.13 / 7.5.4+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-24052 Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an… Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 CRITICAL 9.3 CVE-2025-59286 Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio… 365 Copilot Chat Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.8 CVE-2025-59246EPSS 7% Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002025-10-09 CRITICAL 9.8 CVE-2025-59247 Azure PlayFab Elevation of Privilege Vulnerability Azure Playfab No fix yet Fix from $2,3002025-10-09 CRITICAL 9.6 CVE-2025-59218 Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002025-10-09 CRITICAL 9.3 CVE-2025-59252 Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio… 365 Word Copilot Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.3 CVE-2025-59272 Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information… 365 Copilot Chat Mitigation only Fix from $2,3002025-10-09 HIGH 8.7 CVE-2025-59271 Redis Enterprise Elevation of Privilege Vulnerability Azure Cache For Redis No fix yet Fix from $1,9502025-10-09 CRITICAL 9.3 CVE-2025-55321 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoo… Azure Monitor Mitigation only Fix from $2,3002025-10-09 HIGH 7.6 CVE-2025-59251 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Edge Chromium 140.0.3485.81+ Fix from $1,9502025-09-24 HIGH 7.3 CVE-2025-55322 Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network. Omniparser 2.0.1+ Fix from $1,9502025-09-24 HIGH 7.0 CVE-2025-59220 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacke… Windows 10 21h2 10.0.19044.6332 / 10.0.19045.6332+ Fix from $1,9502025-09-18 HIGH 7.0 CVE-2025-59215 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.6508+ Fix from $1,9502025-09-18 HIGH 7.0 CVE-2025-59216 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized atta… Windows 11 24h2 10.0.26100.6508+ Fix from $1,9502025-09-18 CRITICAL 9.8 CVE-2025-55319 Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network. Visual Studio Code 1.104.0+ Fix from $2,3002025-09-12