Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-54897EPSS 19% Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20100+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54895 Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54896 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20047+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54898 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20047+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54899 Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54894 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-54113 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8422 / 10.0.17763.7792+ Fix from $1,9502025-09-09 HIGH 7.3 CVE-2025-54116 Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 HIGH 7.0 CVE-2025-54114 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an a… Windows 10 1607 10.0.14393.8422 / 10.0.19044.6332+ Fix from $1,9502025-09-09 HIGH 7.0 CVE-2025-54115 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to eleva… Windows 10 1809 10.0.17763.7792 / 10.0.19044.6332+ Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-54110 Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54111 Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 HIGH 7.0 CVE-2025-54108 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a… Windows 11 24h2 10.0.26100.6508+ Fix from $1,9502025-09-09 HIGH 7.0 CVE-2025-54112 Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 MEDIUM 6.7 CVE-2025-54109 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege… Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,6002025-09-09 HIGH 8.8 CVE-2025-54106 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2012 10.0.14393.8422 / 10.0.17763.7792+ Fix from $1,9502025-09-09 HIGH 7.4 CVE-2025-54103 Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.6332 / 10.0.19045.6332+ Fix from $1,9502025-09-09 HIGH 7.0 CVE-2025-54105 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized a… Windows 11 24h2 10.0.25398.1849 / 10.0.26100.6508+ Fix from $1,9502025-09-09 MEDIUM 6.7 CVE-2025-54104 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege… Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,6002025-09-09 HIGH 7.8 CVE-2025-54098 Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54102 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8422 / 10.0.17763.7792+ Fix from $1,9502025-09-09 HIGH 7.0 CVE-2025-54099 Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 MEDIUM 6.7 CVE-2025-54094 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege… Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-54095 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows Server 2008 10.0.14393.8422 / 10.0.17763.7792+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-54096 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows Server 2008 10.0.14393.8422 / 10.0.17763.7792+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-54097 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows Server 2008 10.0.14393.8422 / 10.0.17763.7792+ Fix from $1,6002025-09-09 HIGH 7.8 CVE-2025-54091 Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-54092 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to eleva… Windows 10 1809 10.0.17763.7792 / 10.0.19044.6332+ Fix from $1,9502025-09-09 HIGH 7.0 CVE-2025-54093 Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 MEDIUM 6.7 CVE-2025-53810 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege… Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,6002025-09-09