Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Teams CRITICAL 10.0
CVE-2026-65667

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Teams CRITICAL 9.6
CVE-2026-62896

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Windows Admin Center CRITICAL 9.8
CVE-2026-62873

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Planetary Computer CRITICAL 10.0
CVE-2026-63508

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Azure Sql Managed Instance CRITICAL 10.0
CVE-2026-62836

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileg…

No fix yet
Fix from $2,300 2026-08-07
Azure Sre Agent CRITICAL 9.9
CVE-2026-62830

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Power Apps CRITICAL 9.3
CVE-2026-59118

Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Entra Provisioning Service CRITICAL 9.9
CVE-2026-59115

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Azure Sql Database CRITICAL 10.0
CVE-2026-56162

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Azure Logic Apps CRITICAL 9.6
CVE-2026-56161

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $2,300 2026-08-07
Azure Service Bus CRITICAL 9.9
CVE-2026-50515

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-08-07
Azure Active Directory CRITICAL 9.9
CVE-2026-50481

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.8
CVE-2026-70558

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) wit…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-67689

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated …

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-67688

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacke…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.9
CVE-2026-67622

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attac…

No fix yet
Fix from $2,300 2026-08-06
macOS CRITICAL 9.8
CVE-2026-65400 KEV

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 2…

Fix: 14.8.9 / 15.7.9+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-53984

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's d…

Patch available
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.4
CVE-2026-48088

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /…

Patch available
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-48087

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration …

Patch available
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.9
CVE-2026-48086

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN pr…

Patch available
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-48085

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provision…

Patch available
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-3418

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be …

No fix yet
Fix from $2,300 2026-08-06
Chrome CRITICAL 9.6
CVE-2026-19175

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted H…

Fix: 151.0.7922.109+
Fix from $2,300 2026-08-06
Chrome CRITICAL 9.6
CVE-2026-19171

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a c…

Fix: 151.0.7922.109+
Fix from $2,300 2026-08-06
Chrome CRITICAL 9.6
CVE-2026-19170

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a c…

Fix: 151.0.7922.109+
Fix from $2,300 2026-08-06
Chrome CRITICAL 9.6
CVE-2026-19166

Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 151.0.7922.109+
Fix from $2,300 2026-08-06
Chrome CRITICAL 9.6
CVE-2026-19164

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sand…

Fix: 151.0.7922.109+
Fix from $2,300 2026-08-06
Chrome CRITICAL 9.6
CVE-2026-19157

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape vi…

Fix: 151.0.7922.109+
Fix from $2,300 2026-08-06
Chrome CRITICAL 9.6
CVE-2026-19149

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a craf…

Fix: 151.0.7922.109+
Fix from $2,300 2026-08-06