Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.0 CVE-2025-49699 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502025-07-08 HIGH 8.4 CVE-2025-49695 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-07-08 HIGH 8.4 CVE-2025-49696 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-07-08 HIGH 8.0 CVE-2025-49691 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49693 Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.5624 / 10.0.22631.5624+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49694 Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.25398.1732 / 10.0.26100.4652+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49687 Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49688 Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2012 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49686 Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49689 Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.4 CVE-2025-49690 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a… Windows 10 1809 10.0.17763.7558 / 10.0.19044.6093+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49683 Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.3 CVE-2025-49682 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.6093 / 10.0.19045.6093+ Fix from $1,9502025-07-08 HIGH 7.0 CVE-2025-49685 Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7558 / 10.0.19044.6093+ Fix from $1,9502025-07-08 MEDIUM 6.5 CVE-2025-49681 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,6002025-07-08 MEDIUM 5.5 CVE-2025-49684 Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,6002025-07-08 HIGH 8.8 CVE-2025-49676 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49679 Numeric truncation error in Windows Shell allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.3 CVE-2025-49680 Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.0 CVE-2025-49677 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.5624+ Fix from $1,9502025-07-08 HIGH 7.0 CVE-2025-49678 Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49672 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49673 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49674 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49675 Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49668 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49669 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49667 Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 MEDIUM 6.5 CVE-2025-49670 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,6002025-07-08 MEDIUM 6.5 CVE-2025-49671 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis… Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,6002025-07-08