Vulnerability index

Browse CVEs

458 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-56191 Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. Exchange Online No fix yet Fix from $2,3002026-07-24 CRITICAL 9.9 CVE-2026-56160 Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. Azure Red Hat Openshift No fix yet Fix from $2,3002026-07-24 CRITICAL 9.8 CVE-2026-56165 Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. Account No fix yet Fix from $2,3002026-07-24 CRITICAL 9.9 CVE-2026-50517 Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. 365 Copilot No fix yet Fix from $2,3002026-07-24 CRITICAL 9.8 CVE-2026-47304 Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. .net Framework 8.0.29 / 9.0.18+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-58617 Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. 365 Copilot 2.111.4+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-58594 Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.9 CVE-2026-57092 Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-57089 Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-57090 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-56190 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-56159 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-55944 Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. Dynamics Nav Patch available Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-55040 KEVEPSS 5% Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-55010 Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network. Minecraft Bedrock Dedicated Server No fix yet Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-50518EPSS 11% Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-50487 Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network. Windows 11 24h2 10.0.26100.8875 / 10.0.26100.33158+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-50447 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-50439 Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.6 CVE-2026-50380 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-50330 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-58644 KEVEPSS 45% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-56164 KEVEPSS 22% Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 CRITICAL 9.6 CVE-2026-55008 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to … Exchange Server 15.02.2562.045+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-54995 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-54117 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. Sql Server 2016 13.0.6500.1 / 13.0.7095.1+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-54118 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. Sql Server 2016 13.0.6500.1 / 13.0.7095.1+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-50694 Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-50522 KEVEPSS 77% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 CRITICAL 9.3 CVE-2026-49798 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14