Vulnerability index

Browse CVEs

458 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Azure Logic Apps CRITICAL 9.9
CVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-12
Dynamics 365 CRITICAL 9.1
CVE-2026-42833

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …

Fix: 9.1.45.11+
Fix from $2,300 2026-05-12
Windows 11 23h2 CRITICAL 9.8
CVE-2026-41096

Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.

Fix: 10.0.22631.7079 / 10.0.25398.2330+
Fix from $2,300 2026-05-12
Confluence Saml Sso CRITICAL 9.1
CVE-2026-41103EPSS 5%

Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate pri…

Fix: 1.3.3 / 7.4.0+
Fix from $2,300 2026-05-12
Windows Server 2012 CRITICAL 9.8
CVE-2026-41089EPSS 80%

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $2,300 2026-05-12
Windows 11 23h2 CRITICAL 9.3
CVE-2026-40402

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.20348.5074 / 10.0.22631.7079+
Fix from $2,300 2026-05-12
Dynamics 365 Customer Insights CRITICAL 9.9
CVE-2026-33821

Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-12
Azure Sdk For Java CRITICAL 9.1
CVE-2026-33117

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com…

Fix: 4.10.6+
Fix from $2,300 2026-05-12
Azure Ai Foundry CRITICAL 10.0
CVE-2026-35435

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-07
Azure Managed Instance For Apache Cassandra CRITICAL 9.9
CVE-2026-33109

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-05-07
Azure Cloud Shell CRITICAL 9.6
CVE-2026-35428

Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s…

Mitigation only
Fix from $2,300 2026-05-07
Azure Managed Instance For Apache Cassandra CRITICAL 9.0
CVE-2026-33844

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-05-07
Azure Iot Central CRITICAL 9.9
CVE-2026-21515

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-24
Entra Id CRITICAL 10.0
CVE-2026-35431

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

Mitigation only
Fix from $2,300 2026-04-23
Bing CRITICAL 9.8
CVE-2026-33819

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-04-23
365 Copilot CRITICAL 9.3
CVE-2026-33102

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-23
Purview Ediscovery CRITICAL 10.0
CVE-2026-26150

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-23
Partner Center CRITICAL 9.6
CVE-2026-24303

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-23
Asp.net Core CRITICAL 9.1
CVE-2026-40372EPSS 11%

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

Fix: 10.0.7+
Fix from $2,300 2026-04-21
Windows 10 1607 CRITICAL 9.8
CVE-2026-33824 KEVEPSS 78%

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $2,300 2026-04-14
Power Apps CRITICAL 9.0
CVE-2026-26149

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a networ…

Fix: 3.26032.10.0+
Fix from $2,300 2026-04-14
Bing CRITICAL 9.8
CVE-2026-32186

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-03
Azure Kubernetes Service CRITICAL 9.8
CVE-2026-33105

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Databricks CRITICAL 9.8
CVE-2026-33107

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Ai Foundry CRITICAL 9.8
CVE-2026-32213

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Bing Images CRITICAL 9.8
CVE-2026-32194

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execu…

No fix yet
Fix from $2,300 2026-03-19
Azure Cloud Shell CRITICAL 9.8
CVE-2026-32169

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-03-19
Bing Images CRITICAL 9.8
CVE-2026-32191

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t…

Mitigation only
Fix from $2,300 2026-03-19
Purview CRITICAL 10.0
CVE-2026-26138

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-03-19
365 Copilot Chat CRITICAL 9.9
CVE-2026-26137

Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-03-19