Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-53131 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. Windows 10 1809 10.0.17763.7678 / 10.0.19044.6216+ Fix from $1,9502025-08-12 HIGH 8.1 CVE-2025-50177 Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 HIGH 7.8 CVE-2025-50173 Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 HIGH 7.8 CVE-2025-50176 Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally. Windows 11 22h2 10.0.20348.3989 / 10.0.22621.5768+ Fix from $1,9502025-08-12 HIGH 7.8 CVE-2025-53132 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to… Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 MEDIUM 6.5 CVE-2025-50172 Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network. Windows 10 1809 10.0.17763.7678 / 10.0.19044.6216+ Fix from $1,6002025-08-12 CRITICAL 9.1 CVE-2025-50171 Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. Windows Server 2022 10.0.20348.3989 / 10.0.25398.1791+ Fix from $2,3002025-08-12 HIGH 7.8 CVE-2025-50170 Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privil… Windows 10 1809 10.0.17763.7678 / 10.0.19044.6216+ Fix from $1,9502025-08-12 HIGH 7.5 CVE-2025-50169 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute… Windows 11 24h2 10.0.26100.4851+ Fix from $1,9502025-08-12 CRITICAL 9.8 CVE-2025-50165EPSS 10% Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. Windows 11 24h2 10.0.26100.4851+ Fix from $2,3002025-08-12 HIGH 7.8 CVE-2025-50168 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.5768 / 10.0.22631.5768+ Fix from $1,9502025-08-12 HIGH 7.0 CVE-2025-50167 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to eleva… Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 MEDIUM 6.5 CVE-2025-50166 Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,6002025-08-12 HIGH 8.8 CVE-2025-50163 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8330 / 10.0.17763.7678+ Fix from $1,9502025-08-12 HIGH 8.0 CVE-2025-50160 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8330 / 10.0.17763.7678+ Fix from $1,9502025-08-12 HIGH 8.0 CVE-2025-50162 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8330 / 10.0.17763.7678+ Fix from $1,9502025-08-12 HIGH 8.0 CVE-2025-50164 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8330 / 10.0.17763.7678+ Fix from $1,9502025-08-12 HIGH 7.3 CVE-2025-50161 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 HIGH 7.8 CVE-2025-50155 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges local… Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 HIGH 7.3 CVE-2025-50159 Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 HIGH 7.0 CVE-2025-50158 Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 MEDIUM 6.5 CVE-2025-50154EPSS 26% Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a networ… Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,6002025-08-12 MEDIUM 5.7 CVE-2025-50156 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a networ… Windows Server 2008 10.0.14393.8330 / 10.0.17763.7678+ Fix from $1,6002025-08-12 MEDIUM 5.7 CVE-2025-50157 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a networ… Windows Server 2008 10.0.14393.8330 / 10.0.17763.7678+ Fix from $1,6002025-08-12 HIGH 8.8 CVE-2025-49757 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-49758 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6465.1 / 13.0.7060.1+ Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-49759 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6465.1 / 13.0.7060.1+ Fix from $1,9502025-08-12 HIGH 7.8 CVE-2025-49761 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 HIGH 7.8 CVE-2025-50153 Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 HIGH 7.0 CVE-2025-49762 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a… Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12