Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2025-24074 Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7136 / 10.0.19044.5737+ Fix from $1,9502025-04-08 HIGH 8.8 CVE-2025-21205 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 8.8 CVE-2025-21221 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 8.8 CVE-2025-21222 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.8 CVE-2025-21204EPSS 7% Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 MEDIUM 6.5 CVE-2025-21197 Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't hav… Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,6002025-04-08 MEDIUM 6.5 CVE-2025-21203 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. Windows Server 2008 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,6002025-04-08 HIGH 7.5 CVE-2025-21174 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ… Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 7.0 CVE-2025-21191 Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges local… Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.6 CVE-2025-29815 Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. Edge Chromium 134.0.3124.66+ Fix from $1,9502025-04-04 HIGH 8.8 CVE-2025-25000 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over… Edge Chromium 135.0.3179.54+ Fix from $1,9502025-04-04 HIGH 8.8 CVE-2025-21384 An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a … Azure Health Bot Mitigation only Fix from $1,9502025-04-01 CRITICAL 9.8 CVE-2025-26683 Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network. Azure Playwright Mitigation only Fix from $2,3002025-03-31 MEDIUM 6.5 CVE-2025-29806 No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 129.0.2792.52+ Fix from $1,6002025-03-23 HIGH 7.8 CVE-2025-29795 Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges… Edge Update 1.3.195.45+ Fix from $1,9502025-03-23 HIGH 8.8 CVE-2025-29807 Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. Dataverse Mitigation only Fix from $1,9502025-03-21 HIGH 8.8 CVE-2025-29814 Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. Partner Center Mitigation only Fix from $1,9502025-03-21 HIGH 7.2 CVE-2025-24053 Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. Dataverse Mitigation only Fix from $1,9502025-03-13 HIGH 8.8 CVE-2025-26645 Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.20947 / 10.0.14393.7876+ Fix from $1,9502025-03-11 HIGH 7.5 CVE-2025-26634 Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network. Windows 10 1507 10.0.10240.20915 / 10.0.14393.7785+ Fix from $1,9502025-03-11 HIGH 7.3 CVE-2025-26631 Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. Visual Studio Code 1.98.0+ Fix from $1,9502025-03-11 HIGH 7.0 CVE-2025-26633 KEVEPSS 30% Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. Windows 10 1507 10.0.10240.20947 / 10.0.14393.7876+ Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-26630 Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-26629 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502025-03-11 HIGH 7.3 CVE-2025-25003 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. Visual Studio 2019 16.11.45 / 17.8.19+ Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-25008 Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally. Windows Server 2016 10.0.14393.7876 / 10.0.17763.7009+ Fix from $1,9502025-03-11 HIGH 7.0 CVE-2025-26627 Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges … Azure Arc 1.0.10+ Fix from $1,9502025-03-11 HIGH 7.3 CVE-2025-24998 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. Visual Studio 2017 15.9.71 / 16.11.45+ Fix from $1,9502025-03-11 HIGH 7.8 CVE-2025-24995 Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.20947 / 10.0.14393.7876+ Fix from $1,9502025-03-11 HIGH 7.3 CVE-2025-24994 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.5039 / 10.0.22631.5039+ Fix from $1,9502025-03-11