Vulnerability index

Browse CVEs

458 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2026-70306 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-65791 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-65768 Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to exec… Teams 1.0.0.2026133602+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-62893 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-62878 Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9121+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-62815 Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. Windows 11 23h2 10.0.20348.5440 / 10.0.22631.7517+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-59124 Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. Windows App 2.0.1314.0+ Fix from $2,3002026-08-11 CRITICAL 9.6 CVE-2026-57104 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to ele… Azure Storage Explorer 1.45.0+ Fix from $2,3002026-08-11 CRITICAL 9.4 CVE-2026-50516 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo… Azure Kubernetes Service No fix yet Fix from $2,3002026-08-11 CRITICAL 9.6 CVE-2026-70332 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Online No fix yet Fix from $2,3002026-08-07 CRITICAL 9.1 CVE-2026-68823 Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. Azure Confidential Ledger No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-65667 Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. Teams No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-63508 Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. Planetary Computer No fix yet Fix from $2,3002026-08-07 CRITICAL 9.8 CVE-2026-62873 Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. Windows Admin Center No fix yet Fix from $2,3002026-08-07 CRITICAL 9.6 CVE-2026-62896 Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. Teams No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-62836 Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileg… Azure Sql Managed Instance No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-62830 Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. Azure Sre Agent No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-59115 '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. Entra Provisioning Service No fix yet Fix from $2,3002026-08-07 CRITICAL 9.3 CVE-2026-59118 Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. Power Apps No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-56162 Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. Azure Sql Database No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-50515 Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. Azure Service Bus No fix yet Fix from $2,3002026-08-07 CRITICAL 9.6 CVE-2026-56161 Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. Azure Logic Apps No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-50481 Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. Azure Active Directory No fix yet Fix from $2,3002026-08-07 CRITICAL 9.6 CVE-2026-66321 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over… Edge Chromium 151.0.4129.59+ Fix from $2,3002026-08-04 CRITICAL 10.0 CVE-2026-66803 Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. Azure Cosmos Db No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-58630 Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. Azure App Service For Linux No fix yet Fix from $2,3002026-07-24 CRITICAL 10.0 CVE-2026-57106 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. Purview Data Governance No fix yet Fix from $2,3002026-07-24 CRITICAL 10.0 CVE-2026-56163 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo… Azure Kubernetes Service No fix yet Fix from $2,3002026-07-24 CRITICAL 9.8 CVE-2026-62825 Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. Azure Key Vault No fix yet Fix from $2,3002026-07-24 CRITICAL 9.8 CVE-2026-58275 Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. Azure Dns No fix yet Fix from $2,3002026-07-24