Vulnerability index

Browse CVEs

458 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-23658 Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. Azure Devops No fix yet Fix from $2,3002026-03-19 CRITICAL 9.3 CVE-2026-26105 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20076+ Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-26125 Payment Orchestrator Service Elevation of Privilege Vulnerability Payment Orchestrator Service No fix yet Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-21536 Microsoft Devices Pricing Program Remote Code Execution Vulnerability Devices Pricing Program No fix yet Fix from $2,3002026-03-05 CRITICAL 9.9 CVE-2026-26030 Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within t… Semantic Kernel 1.39.4+ Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-21531 Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network. Azure Conversation Authoring Client Library Mitigation only Fix from $2,3002026-02-10 CRITICAL 9.8 CVE-2026-24300 Azure Front Door Elevation of Privilege Vulnerability Azure Front Door No fix yet Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2026-24302 Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. Azure Arc Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2026-24888 Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject`… Maker.js after 0.19.1 Fix from $2,3002026-01-28 CRITICAL 9.9 CVE-2026-24304 Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. Azure Resource Manager Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-24305 Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-24306 Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. Azure Front Door No fix yet Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-21227 Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile… Azure Logic Apps Mitigation only Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-20963 KEVEPSS 32% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20442+ Fix from $2,3002026-01-13 CRITICAL 9.6 CVE-2025-64675 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform sp… Azure Cosmos Db Mitigation only Fix from $2,3002025-12-19 CRITICAL 10.0 CVE-2025-65037 Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. Azure Container Apps Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.8 CVE-2025-65041 Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. Partner Center Mitigation only Fix from $2,3002025-12-18 CRITICAL 9.0 CVE-2025-64672 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19127.20378+ Fix from $2,3002025-12-09 CRITICAL 9.8 CVE-2025-64656 Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. Azure Application Gateway Mitigation only Fix from $2,3002025-11-26 CRITICAL 9.8 CVE-2025-64657 Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network. Azure Application Gateway Mitigation only Fix from $2,3002025-11-26 CRITICAL 9.8 CVE-2025-64655 Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network. Dynamics Omnichannel Sdk Storage Containers No fix yet Fix from $2,3002025-11-20 CRITICAL 9.8 CVE-2025-62207 Azure Monitor Elevation of Privilege Vulnerability Azure Monitor No fix yet Fix from $2,3002025-11-20 CRITICAL 9.8 CVE-2025-59245 Microsoft SharePoint Online Elevation of Privilege Vulnerability Sharepoint Online No fix yet Fix from $2,3002025-11-20 CRITICAL 10.0 CVE-2025-49752 Azure Bastion Elevation of Privilege Vulnerability Azure Bastion Developer No fix yet Fix from $2,3002025-11-20 CRITICAL 9.8 CVE-2025-60724EPSS 6% Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. 365 Copilot 10.0.14393.8594 / 10.0.17763.8027+ Fix from $2,3002025-11-11 CRITICAL 9.8 CVE-2025-59503 Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network. Azure Compute Resource Provider Mitigation only Fix from $2,3002025-10-23 CRITICAL 9.8 CVE-2025-59273 Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network. Azure Event Grid No fix yet Fix from $2,3002025-10-23 CRITICAL 9.8 CVE-2025-59287 KEVEPSS 100% Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. Windows Server 2012 10.0.14393.8524 / 10.0.17763.7922+ Fix from $2,3002025-10-14 CRITICAL 9.9 CVE-2025-55315EPSS 66% Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security f… Asp.net Core 2.3.6 / 8.0.21+ Fix from $2,3002025-10-14 CRITICAL 9.9 CVE-2025-49708 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. Windows 10 1809 10.0.17763.7919 / 10.0.19044.6456+ Fix from $2,3002025-10-14