Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2025-26636 Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information loca… Windows 11 24h2 10.0.26100.4652+ Fix from $1,6002025-07-08 HIGH 8.8 CVE-2025-49713 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over… Edge Chromium 138.0.3351.65+ Fix from $1,9502025-07-02 HIGH 7.5 CVE-2025-49741 No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Edge Chromium 135.0.3179.98+ Fix from $1,9502025-07-01 HIGH 7.5 CVE-2025-49715 Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to … Dynamics 365 Mitigation only Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-47959EPSS 7% Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code ov… Visual Studio 2022 17.8.22 / 17.10.16+ Fix from $1,9502025-06-13 HIGH 7.5 CVE-2025-30399 Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. Visual Studio 2022 7.4.11 / 7.5.2+ Fix from $1,9502025-06-13 HIGH 7.5 CVE-2025-32711EPSS 8% Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. 365 Copilot No fix yet Fix from $1,9502025-06-11 HIGH 8.4 CVE-2025-32717 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-06-11 HIGH 8.2 CVE-2025-47977 Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized att… Nuance Digital Engagement Platform 5.64.x+ Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-47968 Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. Autoupdate 4.79+ Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-47962 Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally. Windows Software Development Kit 10.0.26100.4188+ Fix from $1,9502025-06-10 HIGH 8.4 CVE-2025-47957 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-06-10 MEDIUM 5.5 CVE-2025-47956 External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally. Windows Security App 1000.27840.0.1000+ Fix from $1,6002025-06-10 HIGH 7.8 CVE-2025-47955 Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-06-10 HIGH 8.4 CVE-2025-47953 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-47176 '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-47175 Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-47174 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-47173 Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-06-10 HIGH 8.8 CVE-2025-47172 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Enterprise Server after 16.0.18526.20396 Fix from $1,9502025-06-10 MEDIUM 6.7 CVE-2025-47171 Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,6002025-06-10 HIGH 7.8 CVE-2025-47170 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-47169 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-47168 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-06-10 HIGH 8.4 CVE-2025-47167 Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.18925.20000+ Fix from $1,9502025-06-10 HIGH 8.8 CVE-2025-47166EPSS 15% Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Enterprise Server 16.0.18526.20396+ Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-47165 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20018+ Fix from $1,9502025-06-10 HIGH 8.4 CVE-2025-47164 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502025-06-10 HIGH 8.8 CVE-2025-47163EPSS 15% Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Enterprise Server 16.0.18526.20396+ Fix from $1,9502025-06-10 HIGH 8.4 CVE-2025-47162 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502025-06-10