Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2025-48799 Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 MEDIUM 6.8 CVE-2025-48001 Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical a… Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,6002025-07-08 MEDIUM 6.8 CVE-2025-48003 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. Windows 10 1809 10.0.17763.7558 / 10.0.19044.6093+ Fix from $1,6002025-07-08 MEDIUM 6.8 CVE-2025-48800 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,6002025-07-08 MEDIUM 5.7 CVE-2025-48002 Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network. Windows 11 24h2 10.0.26100.4652+ Fix from $1,6002025-07-08 HIGH 8.8 CVE-2025-47998 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 8.6 CVE-2025-47994 Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally. 365 Apps Mitigation only Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47996 Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-48000 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 MEDIUM 6.8 CVE-2025-47999 Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,6002025-07-08 HIGH 7.8 CVE-2025-47987 Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47991 Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47993 Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.25398.1732 / 10.0.26100.4652+ Fix from $1,9502025-07-08 HIGH 7.5 CVE-2025-47988 Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent net… Azure Monitor Agent 1.35.1+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-47986 Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47982 Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47985 Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.5 CVE-2025-47984EPSS 16% Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 CRITICAL 9.8 CVE-2025-47981EPSS 32% Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $2,3002025-07-08 MEDIUM 6.5 CVE-2025-47978 Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. Windows Server 2022 10.0.20348.3932 / 10.0.25398.1732+ Fix from $1,6002025-07-08 MEDIUM 6.2 CVE-2025-47980 Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information local… Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,6002025-07-08 HIGH 8.0 CVE-2025-47972 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authoriz… Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47971 Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47973 Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47976 Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.0 CVE-2025-47975 Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 8.0 CVE-2025-47178 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker… Configuration Manager 2503 5.00.9135.1003+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-47159 Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 8.1 CVE-2025-33054 Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network. Windows 11 22h2 10.0.22621.5624 / 10.0.22631.5624+ Fix from $1,9502025-07-08 MEDIUM 6.0 CVE-2025-21195 Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally. Azure Service Fabric 10.1+ Fix from $1,6002025-07-08