Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-65667 Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. Teams No fix yet Fix from $2,3002026-08-07 CRITICAL 9.6 CVE-2026-62896 Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. Teams No fix yet Fix from $2,3002026-08-07 CRITICAL 9.8 CVE-2026-62873 Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. Windows Admin Center No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-63508 Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. Planetary Computer No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-62836 Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileg… Azure Sql Managed Instance No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-62830 Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. Azure Sre Agent No fix yet Fix from $2,3002026-08-07 CRITICAL 9.3 CVE-2026-59118 Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. Power Apps No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-59115 '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. Entra Provisioning Service No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-56162 Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. Azure Sql Database No fix yet Fix from $2,3002026-08-07 CRITICAL 9.6 CVE-2026-56161 Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. Azure Logic Apps No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-50515 Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. Azure Service Bus No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-50481 Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. Azure Active Directory No fix yet Fix from $2,3002026-08-07 CRITICAL 9.8 CVE-2026-70558 Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) wit… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-67689 SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated … No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-67688 ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacke… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.9 CVE-2026-67622 Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attac… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-65400 KEV An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 2… macOS 14.8.9 / 15.7.9+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-53984 Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's d… Patch available Fix from $2,3002026-08-06 CRITICAL 9.4 CVE-2026-48088 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /… Patch available Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-48087 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration … Patch available Fix from $2,3002026-08-06 CRITICAL 9.9 CVE-2026-48086 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN pr… Patch available Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-48085 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provision… Patch available Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-3418 The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be … No fix yet Fix from $2,3002026-08-06 CRITICAL 9.6 CVE-2026-19175 Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted H… Chrome 151.0.7922.109+ Fix from $2,3002026-08-06 CRITICAL 9.6 CVE-2026-19171 Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a c… Chrome 151.0.7922.109+ Fix from $2,3002026-08-06 CRITICAL 9.6 CVE-2026-19170 Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a c… Chrome 151.0.7922.109+ Fix from $2,3002026-08-06 CRITICAL 9.6 CVE-2026-19166 Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a… Chrome 151.0.7922.109+ Fix from $2,3002026-08-06 CRITICAL 9.6 CVE-2026-19164 Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sand… Chrome 151.0.7922.109+ Fix from $2,3002026-08-06 CRITICAL 9.6 CVE-2026-19157 Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape vi… Chrome 151.0.7922.109+ Fix from $2,3002026-08-06 CRITICAL 9.6 CVE-2026-19149 Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a craf… Chrome 151.0.7922.109+ Fix from $2,3002026-08-06