Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2025-27490 Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.5737 / 10.0.19045.5737+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-27484 Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate pri… Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-27485 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ… Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-27486 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ… Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 8.8 CVE-2025-27481 Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 8.1 CVE-2025-27480EPSS 10% Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 8.1 CVE-2025-27482 Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. Windows Server 2016 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-27483 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-27479 Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network. Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 7.0 CVE-2025-27478 Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 8.8 CVE-2025-27477 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-27476 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7136 / 10.0.19044.5737+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-27473 Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.0 CVE-2025-27475 Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.5189 / 10.0.22631.5189+ Fix from $1,9502025-04-08 MEDIUM 6.5 CVE-2025-27474 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a netw… Windows Server 2008 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,6002025-04-08 MEDIUM 5.4 CVE-2025-27472 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. Windows 10 1507 10.0.10240.20978+ Fix from $1,6002025-04-08 HIGH 7.8 CVE-2025-27467 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7136 / 10.0.19044.5737+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-27469 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a netw… Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-27470 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ… Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 MEDIUM 5.9 CVE-2025-27471 Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,6002025-04-08 HIGH 7.8 CVE-2025-26688 Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-26682 Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. Asp.net Core 8.0.15 / 9.0.4+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-26686 Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-26687 Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. 365 Copilot 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 8.4 CVE-2025-26678 Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally. Windows 10 1809 10.0.17763.7136 / 10.0.19044.5737+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-26679 Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-26680 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ… Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 MEDIUM 6.7 CVE-2025-26681 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.5737 / 10.0.19045.5737+ Fix from $1,6002025-04-08 MEDIUM 6.5 CVE-2025-26676 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows Server 2008 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,6002025-04-08 HIGH 8.1 CVE-2025-26671 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08