Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-49739 Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network. Visual Studio 15.9.75 / 16.11.49+ Fix from $1,9502025-07-08 HIGH 8.1 CVE-2025-49735 Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. Windows Server 2012 10.0.14393.8148 / 10.0.17763.7434+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49733 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7558 / 10.0.19044.6093+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49738 Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.17.4.0+ Fix from $1,9502025-07-08 HIGH 7.0 CVE-2025-49737 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to eleva… Teams 25163.3001.3726.6503+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49729 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49730 Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49732 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49723 Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally. Windows 10 1809 10.0.17763.7558 / 10.0.19044.6093+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49724EPSS 8% Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network. Windows 10 1809 10.0.17763.7558 / 10.0.19044.6093+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49725 Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49726 Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 7.0 CVE-2025-49727 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 8.5 CVE-2025-49717 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. Sql Server 2019 15.0.2135.5 / 15.0.4435.7+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49721 Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.5 CVE-2025-49718 Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network. Sql Server 2019 15.0.2135.5 / 15.0.4435.7+ Fix from $1,9502025-07-08 HIGH 7.5 CVE-2025-49719EPSS 11% Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network. Sql Server 2016 13.0.6460.7 / 13.0.7055.9+ Fix from $1,9502025-07-08 MEDIUM 5.7 CVE-2025-49722 Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,6002025-07-08 HIGH 7.8 CVE-2025-49705 Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49711 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20027+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49714 Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally. Python 2025.8.1+ Fix from $1,9502025-07-08 HIGH 7.5 CVE-2025-49716 Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 MEDIUM 6.5 CVE-2025-49706 KEVEPSS 100% Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Sharepoint Enterprise Server 16.0.18526.20424+ Fix from $1,6002025-07-08 HIGH 8.8 CVE-2025-49701 Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.18526.20424+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49704 KEVEPSS 100% Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server Mitigation only Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49702 Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49703 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-07-08 HIGH 8.4 CVE-2025-49697 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20027+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49698 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49700 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-07-08