Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-19190 A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Se… No fix yet Fix from $1,9502026-08-07 HIGH 7.1 CVE-2026-49746 Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases… No fix yet Fix from $1,9502026-08-07 MEDIUM 5.5 CVE-2026-45204 Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kernel null pointer dereference i… No fix yet Fix from $1,6002026-08-07 HIGH 7.8 CVE-2026-45198 Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using … No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-19189 A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows… No fix yet Fix from $1,9502026-08-07 CRITICAL 9.6 CVE-2026-70332 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Online No fix yet Fix from $2,3002026-08-07 CRITICAL 9.1 CVE-2026-68823 Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. Azure Confidential Ledger No fix yet Fix from $2,3002026-08-07 HIGH 8.8 CVE-2026-65668 Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. Purview Ediscovery No fix yet Fix from $1,9502026-08-07 CRITICAL 10.0 CVE-2026-65667 Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. Teams No fix yet Fix from $2,3002026-08-07 CRITICAL 9.6 CVE-2026-62896 Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. Teams No fix yet Fix from $2,3002026-08-07 CRITICAL 9.8 CVE-2026-62873 Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. Windows Admin Center No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-63508 Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. Planetary Computer No fix yet Fix from $2,3002026-08-07 HIGH 7.5 CVE-2026-62918 Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. Teams No fix yet Fix from $1,9502026-08-07 CRITICAL 10.0 CVE-2026-62836 Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileg… Azure Sql Managed Instance No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-62830 Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. Azure Sre Agent No fix yet Fix from $2,3002026-08-07 CRITICAL 9.3 CVE-2026-59118 Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. Power Apps No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-59115 '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. Entra Provisioning Service No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-56162 Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. Azure Sql Database No fix yet Fix from $2,3002026-08-07 CRITICAL 9.6 CVE-2026-56161 Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. Azure Logic Apps No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-50515 Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. Azure Service Bus No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-50481 Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. Azure Active Directory No fix yet Fix from $2,3002026-08-07 HIGH 8.8 CVE-2026-49163 Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elev… Application Insights Profiler No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-8325 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage th… No fix yet Fix from $1,9502026-08-06 HIGH 7.8 CVE-2026-7867 A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option … No fix yet Fix from $1,9502026-08-06 HIGH 7.8 CVE-2026-7406 A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious a… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.5 CVE-2026-7405 A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handl… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.2 CVE-2026-71430 node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result… No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-70636 Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh e… No fix yet Fix from $1,9502026-08-06 HIGH 7.8 CVE-2026-70632 FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decod… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.5 CVE-2026-70631 FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in li… No fix yet Fix from $1,6002026-08-06