Vulnerability index

Browse CVEs

458 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Azure Devops CRITICAL 9.8
CVE-2026-23658

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-03-19
Sharepoint Server CRITICAL 9.3
CVE-2026-26105

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20076+
Fix from $2,300 2026-03-10
Payment Orchestrator Service CRITICAL 9.8
CVE-2026-26125

Payment Orchestrator Service Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-03-05
Devices Pricing Program CRITICAL 9.8
CVE-2026-21536

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

No fix yet
Fix from $2,300 2026-03-05
Semantic Kernel CRITICAL 9.9
CVE-2026-26030

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within t…

Fix: 1.39.4+
Fix from $2,300 2026-02-19
Azure Conversation Authoring Client Library CRITICAL 9.8
CVE-2026-21531

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-02-10
Azure Front Door CRITICAL 9.8
CVE-2026-24300

Azure Front Door Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-02-05
Azure Arc CRITICAL 9.8
CVE-2026-24302

Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-02-05
Maker.js CRITICAL 9.8
CVE-2026-24888

Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject`…

Fix: after 0.19.1
Fix from $2,300 2026-01-28
Azure Resource Manager CRITICAL 9.9
CVE-2026-24304

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-01-23
Entra Id CRITICAL 9.8
CVE-2026-24305

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-01-22
Azure Front Door CRITICAL 9.8
CVE-2026-24306

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-01-22
Azure Logic Apps CRITICAL 9.8
CVE-2026-21227

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…

Mitigation only
Fix from $2,300 2026-01-22
Sharepoint Server CRITICAL 9.8
CVE-2026-20963 KEVEPSS 32%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19127.20442+
Fix from $2,300 2026-01-13
Azure Cosmos Db CRITICAL 9.6
CVE-2025-64675

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform sp…

Mitigation only
Fix from $2,300 2025-12-19
Azure Container Apps CRITICAL 10.0
CVE-2025-65037

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2025-12-18
Partner Center CRITICAL 9.8
CVE-2025-65041

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-12-18
Sharepoint Server CRITICAL 9.0
CVE-2025-64672

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19127.20378+
Fix from $2,300 2025-12-09
Azure Application Gateway CRITICAL 9.8
CVE-2025-64656

Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-11-26
Azure Application Gateway CRITICAL 9.8
CVE-2025-64657

Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-11-26
Dynamics Omnichannel Sdk Storage Containers CRITICAL 9.8
CVE-2025-64655

Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-11-20
Azure Monitor CRITICAL 9.8
CVE-2025-62207

Azure Monitor Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-11-20
Sharepoint Online CRITICAL 9.8
CVE-2025-59245

Microsoft SharePoint Online Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-11-20
Azure Bastion Developer CRITICAL 10.0
CVE-2025-49752

Azure Bastion Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-11-20
365 Copilot CRITICAL 9.8
CVE-2025-60724EPSS 6%

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $2,300 2025-11-11
Azure Compute Resource Provider CRITICAL 9.8
CVE-2025-59503

Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-10-23
Azure Event Grid CRITICAL 9.8
CVE-2025-59273

Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-10-23
Windows Server 2012 CRITICAL 9.8
CVE-2025-59287 KEVEPSS 100%

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8524 / 10.0.17763.7922+
Fix from $2,300 2025-10-14
Asp.net Core CRITICAL 9.9
CVE-2025-55315EPSS 66%

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security f…

Fix: 2.3.6 / 8.0.21+
Fix from $2,300 2025-10-14
Windows 10 1809 CRITICAL 9.9
CVE-2025-49708

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.17763.7919 / 10.0.19044.6456+
Fix from $2,300 2025-10-14