Vulnerability index

Browse CVEs

458 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-42823 Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. Azure Logic Apps Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-42833 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over … Dynamics 365 9.1.45.11+ Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-41096 Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. Windows 11 23h2 10.0.22631.7079 / 10.0.25398.2330+ Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-41103EPSS 5% Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate pri… Confluence Saml Sso 1.3.3 / 7.4.0+ Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-41089EPSS 80% Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. Windows Server 2012 10.0.14393.9140 / 10.0.17763.8755+ Fix from $2,3002026-05-12 CRITICAL 9.3 CVE-2026-40402 Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. Windows 11 23h2 10.0.20348.5074 / 10.0.22631.7079+ Fix from $2,3002026-05-12 CRITICAL 9.9 CVE-2026-33821 Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. Dynamics 365 Customer Insights Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-33117 The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com… Azure Sdk For Java 4.10.6+ Fix from $2,3002026-05-12 CRITICAL 10.0 CVE-2026-35435 Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. Azure Ai Foundry Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.9 CVE-2026-33109 Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. Azure Managed Instance For Apache Cassandra Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.6 CVE-2026-35428 Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s… Azure Cloud Shell Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.0 CVE-2026-33844 Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. Azure Managed Instance For Apache Cassandra Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.9 CVE-2026-21515 Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. Azure Iot Central No fix yet Fix from $2,3002026-04-24 CRITICAL 10.0 CVE-2026-35431 Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. Entra Id Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-33819 Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. Bing Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.3 CVE-2026-33102 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 365 Copilot Mitigation only Fix from $2,3002026-04-23 CRITICAL 10.0 CVE-2026-26150 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. Purview Ediscovery Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.6 CVE-2026-24303 Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. Partner Center No fix yet Fix from $2,3002026-04-23 CRITICAL 9.1 CVE-2026-40372EPSS 11% Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. Asp.net Core 10.0.7+ Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-33824 KEVEPSS 78% Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $2,3002026-04-14 CRITICAL 9.0 CVE-2026-26149 Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a networ… Power Apps 3.26032.10.0+ Fix from $2,3002026-04-14 CRITICAL 9.8 CVE-2026-32186 Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. Bing No fix yet Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-33105 Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Azure Kubernetes Service Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-33107 Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. Azure Databricks Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-32213 Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. Azure Ai Foundry Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-32194 Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execu… Bing Images No fix yet Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-32169 Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. Azure Cloud Shell Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-32191 Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t… Bing Images Mitigation only Fix from $2,3002026-03-19 CRITICAL 10.0 CVE-2026-26138 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. Purview Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.9 CVE-2026-26137 Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. 365 Copilot Chat No fix yet Fix from $2,3002026-03-19