Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-53809 Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. Windows 11 24h2 10.0.26100.6508+ Fix from $1,6002025-09-09 HIGH 7.5 CVE-2025-53805 Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network. Windows 11 22h2 10.0.20348.4106 / 10.0.22621.5909+ Fix from $1,9502025-09-09 HIGH 7.0 CVE-2025-53807 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized atta… Windows 10 1809 10.0.17763.7792 / 10.0.19044.6332+ Fix from $1,9502025-09-09 MEDIUM 6.7 CVE-2025-53808 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privilege… Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-53806 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows Server 2008 10.0.14393.8422 / 10.0.17763.7792+ Fix from $1,6002025-09-09 MEDIUM 5.5 CVE-2025-53804 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,6002025-09-09 HIGH 7.8 CVE-2025-53800 No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8422 / 10.0.17763.7792+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-53801 Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 HIGH 7.0 CVE-2025-53802 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.6332 / 10.0.19045.6332+ Fix from $1,9502025-09-09 MEDIUM 5.5 CVE-2025-53799 Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. 365 Copilot 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,6002025-09-09 MEDIUM 5.5 CVE-2025-53803 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-53796 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows Server 2008 10.0.14393.8422 / 10.0.17763.7792+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-53797 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows Server 2008 10.0.14393.8422 / 10.0.17763.7792+ Fix from $1,6002025-09-09 MEDIUM 6.5 CVE-2025-53798 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows Server 2008 10.0.14393.8422 / 10.0.17763.7792+ Fix from $1,6002025-09-09 HIGH 7.0 CVE-2025-49734 Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. Powershell 7.4.12 / 7.5.3+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-49692 Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. Azure Connected Machine Agent 1.49+ Fix from $1,9502025-09-09 MEDIUM 5.3 CVE-2025-47997 Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose i… Sql Server 2016 13.0.6470.1 / 13.0.7065.1+ Fix from $1,6002025-09-09 CRITICAL 9.0 CVE-2025-55244 Azure Bot Service Elevation of Privilege Vulnerability Azure Ai Bot Service No fix yet Fix from $2,3002025-09-04 HIGH 7.5 CVE-2025-55242 Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network. Xbox Gaming Services No fix yet Fix from $1,9502025-09-04 CRITICAL 10.0 CVE-2025-55241 Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002025-09-04 CRITICAL 9.8 CVE-2025-54914 Azure Networking Elevation of Privilege Vulnerability Azure Networking No fix yet Fix from $2,3002025-09-04 HIGH 7.5 CVE-2025-55238 Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability Dynamics 365 No fix yet Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-9491EPSS 69% Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary … Windows 11 23h2 Mitigation only Fix from $1,9502025-08-26 HIGH 7.8 CVE-2025-55230 Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-08-21 HIGH 7.5 CVE-2025-55231 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to exe… Windows Server 2012 10.0.14393.8416 / 10.0.17763.7783+ Fix from $1,9502025-08-21 MEDIUM 5.3 CVE-2025-55229 Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,6002025-08-21 CRITICAL 9.8 CVE-2025-53795 Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network. Pc Manager Mitigation only Fix from $2,3002025-08-21 CRITICAL 9.8 CVE-2025-53763 Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. Purview Data Governance No fix yet Fix from $2,3002025-08-21 HIGH 7.8 CVE-2025-53789 Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-08-12 HIGH 7.5 CVE-2025-53793 Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network. Azure Stack Hub 1.2406.1.23 / 1.2408.1.50+ Fix from $1,9502025-08-12