Vulnerabilities (CVE)

Total 400115 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-53782 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-06-17 N/A 8.4 HIGH
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
CVE-2025-53781 1 Microsoft 22 Dcadsv5-series Azure Vm, Dcadsv5-series Azure Vm Firmware, Dcasv5-series Azure Vm and 19 more 2026-06-17 N/A 7.7 HIGH
Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a network.
CVE-2025-53779 1 Microsoft 1 Windows Server 2025 2026-06-17 N/A 7.2 HIGH
Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
CVE-2025-53778 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2026-06-17 N/A 8.8 HIGH
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
CVE-2025-53774 1 Microsoft 1 365 Copilot Chat 2026-06-17 N/A 6.5 MEDIUM
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
CVE-2025-53773 1 Microsoft 1 Visual Studio 2022 2026-06-17 N/A 7.8 HIGH
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2025-53772 1 Microsoft 1 Web Deploy 4.0 2026-06-17 N/A 8.8 HIGH
Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.
CVE-2025-53771 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 6.5 MEDIUM
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-53769 1 Microsoft 1 Windows Security App 2026-06-17 N/A 5.5 MEDIUM
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
CVE-2025-53768 1 Microsoft 9 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 6 more 2026-06-17 N/A 7.8 HIGH
Use after free in Xbox allows an authorized attacker to elevate privileges locally.
CVE-2025-53767 1 Microsoft 1 Azure Openai 2026-06-17 N/A 10.0 CRITICAL
Azure OpenAI Elevation of Privilege Vulnerability
CVE-2025-53766 1 Microsoft 17 365 Copilot, Office, Windows 10 1507 and 14 more 2026-06-17 N/A 9.8 CRITICAL
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVE-2025-53765 1 Microsoft 2 Azure App Service On Azure Stack, Azure Stack Hub 2026-06-17 N/A 4.4 MEDIUM
Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.
CVE-2025-53763 1 Microsoft 1 Purview Data Governance 2026-06-17 N/A 9.8 CRITICAL
Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-53762 1 Microsoft 1 Purview 2026-06-17 N/A 8.7 HIGH
Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network.
CVE-2025-53761 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 7.8 HIGH
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-53760 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 7.1 HIGH
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2025-53759 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 7.8 HIGH
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-53758 2026-06-17 N/A N/A
This vulnerability exists in Digisol DG-GR6821AC Router due to use of default admin credentials at its web management interface. An attacker with physical access could exploit this vulnerability by extracting the firmware and reverse engineer the binary data to access the hardcoded default credentials stored in the firmware of the targeted device. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted device.
CVE-2025-53757 2026-06-17 N/A N/A
This vulnerability exists in Digisol DG-GR6821AC Router due to misconfiguration of both Secure and HttpOnly flags on session cookies associated with the router web interface. A remote attacker could exploit this vulnerability by capturing the session cookies transmitted over an unsecure HTTP connection. Successful exploitation of this vulnerability could allow the attacker to obtain sensitive information from the targeted device.