Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2025-55245 Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally. Xbox Gaming Services 30.104.13001.0+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-55316 External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally. Azure Connected Machine Agent 1.56+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-55317 Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges loca… Autoupdate 4.80+ Fix from $1,9502025-09-09 HIGH 7.5 CVE-2025-55243 Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a networ… Officeplus 3.10.0.26585+ Fix from $1,9502025-09-09 CRITICAL 9.8 CVE-2025-55232 Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. Hpc Pack 6.3.8352+ Fix from $2,3002025-09-09 CRITICAL 9.8 CVE-2025-55234EPSS 20% SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could p… Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $2,3002025-09-09 HIGH 7.8 CVE-2025-55228 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to… Windows 10 21h2 10.0.19044.6332 / 10.0.19045.6332+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-55236 Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally. Windows 10 1809 10.0.17763.7792 / 10.0.19044.6332+ Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-55227 Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges… Sql Server 2016 13.0.6470.1 / 13.0.7065.1+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-55224 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to… Windows 10 1809 10.0.17763.7792 / 10.0.19044.6332+ Fix from $1,9502025-09-09 MEDIUM 6.7 CVE-2025-55226 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execu… Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-55225 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows Server 2008 10.0.14393.8422 / 10.0.17763.7792+ Fix from $1,6002025-09-09 HIGH 8.8 CVE-2025-54918EPSS 19% Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54916 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 HIGH 7.5 CVE-2025-54919 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to… Windows 10 1809 10.0.17763.7792 / 10.0.19044.6332+ Fix from $1,9502025-09-09 HIGH 7.0 CVE-2025-55223 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to eleva… Windows 10 1809 10.0.17763.7792 / 10.0.19044.6332+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54912 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54913 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an auth… Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 HIGH 7.3 CVE-2025-54911 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 MEDIUM 6.7 CVE-2025-54915 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege… Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,6002025-09-09 HIGH 8.4 CVE-2025-54910 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54906 Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54907 Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54908 Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-09-09 HIGH 7.1 CVE-2025-54905 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 365 Apps Mitigation only Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54900 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20047+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54902 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20047+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54903 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20047+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54904 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20047+ Fix from $1,9502025-09-09 MEDIUM 5.5 CVE-2025-54901 Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 365 Apps Mitigation only Fix from $1,6002025-09-09