Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.2 CVE-2025-29957 Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,6002025-05-13 MEDIUM 5.9 CVE-2025-29954 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a netw… Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,6002025-05-13 MEDIUM 5.5 CVE-2025-29955 Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally. Windows 11 24h2 10.0.25398.1611 / 10.0.26100.4061+ Fix from $1,6002025-05-13 MEDIUM 5.4 CVE-2025-29956 Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,6002025-05-13 HIGH 8.8 CVE-2025-29840 Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 HIGH 7.0 CVE-2025-29838 Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.4061+ Fix from $1,9502025-05-13 HIGH 7.0 CVE-2025-29841 Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorize… Windows 10 21h2 10.0.19044.5854 / 10.0.19045.5854+ Fix from $1,9502025-05-13 MEDIUM 6.5 CVE-2025-29836 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,6002025-05-13 MEDIUM 5.5 CVE-2025-29837 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,6002025-05-13 HIGH 7.7 CVE-2025-29833 Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 HIGH 7.5 CVE-2025-29831 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8066 / 10.0.17763.7314+ Fix from $1,9502025-05-13 MEDIUM 6.5 CVE-2025-29830 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a netw… Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,6002025-05-13 MEDIUM 6.5 CVE-2025-29832 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,6002025-05-13 MEDIUM 6.5 CVE-2025-29835 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,6002025-05-13 HIGH 8.8 CVE-2025-29826 Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. Dataverse 3.4.0.1406+ Fix from $1,9502025-05-13 HIGH 7.0 CVE-2025-27468 Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 MEDIUM 6.7 CVE-2025-27488 Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally. Windows Hardware Lab Kit 10.1.17763.7010 / 10.1.19041.5609+ Fix from $1,6002025-05-13 MEDIUM 6.5 CVE-2025-26685 Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network. Defender For Identity Mitigation only Fix from $1,6002025-05-13 MEDIUM 5.5 CVE-2025-29829 Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,6002025-05-13 HIGH 7.8 CVE-2025-24063 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 HIGH 7.5 CVE-2025-26677 Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network. Windows Server 2016 10.0.14393.8066 / 10.0.17763.7314+ Fix from $1,9502025-05-13 HIGH 7.1 CVE-2025-21264 Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Visual Studio Code 1.100.1+ Fix from $1,9502025-05-13 MEDIUM 6.7 CVE-2025-26684 External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. Defender For Endpoint 101.25032.0008+ Fix from $1,6002025-05-13 HIGH 7.5 CVE-2025-47733 Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network Power Apps Mitigation only Fix from $1,9502025-05-08 CRITICAL 9.8 CVE-2025-29813 Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. Azure Devops Mitigation only Fix from $2,3002025-05-08 CRITICAL 9.8 CVE-2025-29972 Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. Azure Storage Resource Provider Mitigation only Fix from $2,3002025-05-08 CRITICAL 9.8 CVE-2025-47732 Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. Dataverse Mitigation only Fix from $2,3002025-05-08 HIGH 8.8 CVE-2025-29827 Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. Azure Automation Mitigation only Fix from $1,9502025-05-08 HIGH 7.5 CVE-2025-33072 Improper access control in Azure allows an unauthorized attacker to disclose information over a network. Msagsfeedback.azurewebsites.net Mitigation only Fix from $1,9502025-05-08 MEDIUM 6.5 CVE-2025-29825 User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing … Edge Chromium 136.0.3240.50+ Fix from $1,6002025-05-02