Vulnerability index

Browse CVEs

458 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Exchange Online CRITICAL 10.0
CVE-2026-56191

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

No fix yet
Fix from $2,300 2026-07-24
Azure Red Hat Openshift CRITICAL 9.9
CVE-2026-56160

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Account CRITICAL 9.8
CVE-2026-56165

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-24
365 Copilot CRITICAL 9.9
CVE-2026-50517

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-24
.net Framework CRITICAL 9.8
CVE-2026-47304

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

Fix: 8.0.29 / 9.0.18+
Fix from $2,300 2026-07-14
365 Copilot CRITICAL 9.8
CVE-2026-58617

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

Fix: 2.111.4+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-58594

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.9
CVE-2026-57092

Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-57089

Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-57090

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-56190

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-56159

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Dynamics Nav CRITICAL 9.8
CVE-2026-55944

Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.

Patch available
Fix from $2,300 2026-07-14
Sharepoint Server CRITICAL 9.1
CVE-2026-55040 KEVEPSS 5%

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Minecraft Bedrock Dedicated Server CRITICAL 9.8
CVE-2026-55010

Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-50518EPSS 11%

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 11 24h2 CRITICAL 9.8
CVE-2026-50487

Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-50447

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-50439

Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.6
CVE-2026-50380

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-50330

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-58644 KEVEPSS 45%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-56164 KEVEPSS 22%

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Exchange Server CRITICAL 9.6
CVE-2026-55008

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …

Fix: 15.02.2562.045+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-54995

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Sql Server 2016 CRITICAL 9.8
CVE-2026-54117

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

Fix: 13.0.6500.1 / 13.0.7095.1+
Fix from $2,300 2026-07-14
Sql Server 2016 CRITICAL 9.8
CVE-2026-54118

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

Fix: 13.0.6500.1 / 13.0.7095.1+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-50694

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-50522 KEVEPSS 77%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.3
CVE-2026-49798

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14