Vulnerability index

Browse CVEs

611 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
365 Apps MEDIUM 5.5
CVE-2026-70323

Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70325

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70316

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70318

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70319

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70320

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70322

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps HIGH 7.8
CVE-2026-70313

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,900 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70312

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
365 Apps MEDIUM 5.5
CVE-2026-70314

Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
Power Bi Report Server HIGH 8.8
CVE-2026-65811

Improper input validation in Power BI allows an authorized attacker to execute code over a network.

No fix yet
Fix from $4,900 2026-08-11
Sharepoint Server HIGH 8.1
CVE-2026-63520

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19725.20522+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 8.1
CVE-2026-61363

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 8.1
CVE-2026-59134

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Edge MEDIUM 5.4
CVE-2026-62828

Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.

No fix yet
Fix from $1,600 2026-07-28
Surface Management Services HIGH 8.8
CVE-2026-54120

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2026-07-24
365 Apps MEDIUM 5.5
CVE-2026-55124

Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Fix: 16.0.10417.20175 / 16.0.19725.20434+
Fix from $1,600 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-50670

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-50417

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.8
CVE-2026-50370

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.5
CVE-2026-50328

Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-55899

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
Edge Chromium HIGH 7.5
CVE-2026-58292

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium HIGH 8.8
CVE-2026-57985

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Visual Studio Code MEDIUM 5.5
CVE-2026-48569

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Fix: 1.123.2+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47641

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-45636

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 11 26h1 HIGH 7.8
CVE-2026-44811

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.28000.2269+
Fix from $1,950 2026-06-09
Visual Studio Code HIGH 8.1
CVE-2026-40376

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Fix: 1.123.2+
Fix from $1,950 2026-06-09
Azure Virtual Network Gateway HIGH 8.8
CVE-2026-40411

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2026-05-22