Vulnerability index

Browse CVEs

33 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Teams CRITICAL 9.8
CVE-2026-65768

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to exec…

Fix: 1.0.0.2026133602+
Fix from $5,750 2026-08-11
Application Insights Profiler HIGH 8.8
CVE-2026-49163

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elev…

No fix yet
Fix from $1,950 2026-08-07
Visual Studio Code MEDIUM 5.5
CVE-2026-45496

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a secu…

Fix: 1.128.1+
Fix from $1,600 2026-07-14
Visual Studio Code HIGH 8.4
CVE-2026-45482

Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attack…

Fix: 1.123.2+
Fix from $1,950 2026-06-09
Sharepoint Server HIGH 8.8
CVE-2026-45454

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execut…

Fix: 16.0.19725.20384+
Fix from $1,950 2026-06-09
Azure Kubernetes Service HIGH 8.8
CVE-2026-32193

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to…

Fix: 2026-02-13.5+
Fix from $1,950 2026-06-09
Live Preview MEDIUM 5.5
CVE-2026-41612

Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.

Fix: 0.4.19+
Fix from $1,600 2026-05-12
Aci Confidential Containers MEDIUM 6.7
CVE-2026-26124

'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $1,600 2026-03-05
Azure Logic Apps CRITICAL 9.8
CVE-2026-21227

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…

Mitigation only
Fix from $2,300 2026-01-22
Github Copilot Chat MEDIUM 6.8
CVE-2025-62449

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized atta…

Fix: 0.32.0+
Fix from $1,600 2025-11-11
Onedrive MEDIUM 6.5
CVE-2025-60722

Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privi…

Fix: 7.42+
Fix from $1,600 2025-11-11
Azure Stack Hub HIGH 7.5
CVE-2025-53793

Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.

Fix: 1.2406.1.23 / 1.2408.1.50+
Fix from $1,950 2025-08-12
365 Apps HIGH 7.8
CVE-2025-47176

'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.

No fix yet
Fix from $1,950 2025-06-10
Azure Ai Document Intelligence Studio CRITICAL 9.8
CVE-2025-30387

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a …

Mitigation only
Fix from $2,300 2025-05-13
Windows 10 1507 MEDIUM 6.8
CVE-2024-49082

Windows File Explorer Information Disclosure Vulnerability

Fix: 10.0.10240.20857 / 10.0.14393.7606+
Fix from $1,600 2024-12-12
Defender For Iot HIGH 8.8
CVE-2024-29053

Microsoft Defender for IoT Remote Code Execution Vulnerability

Fix: 24.1.3+
Fix from $1,950 2024-04-09
Confidental Containers CRITICAL 9.0
CVE-2024-21400

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Fix: 0.3.3+
Fix from $2,300 2024-03-12
Azure Arc Enabled Servers HIGH 7.0
CVE-2023-38176

Azure Arc-Enabled Servers Elevation of Privilege Vulnerability

Fix: 1.33.02399.0+
Fix from $1,950 2023-08-08
Binwalk HIGH 7.8
CVE-2022-4510EPSS 22%

A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesyst…

Fix: 2.3.3+
Fix from $1,950 2023-01-26
Windows Defender For Endpoint MEDIUM 5.5
CVE-2022-29799EPSS 12%

A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeSt…

Patch available
Fix from $1,600 2022-09-21
Windows 10 1507 HIGH 7.8
CVE-2022-21999 KEVEPSS 42%

Windows Print Spooler Elevation of Privilege Vulnerability

Fix: 10.0.10240.19204 / 10.0.14393.4946+
Fix from $1,950 2022-02-09
Windows 10 1507 HIGH 8.8
CVE-2021-40444 KEVEPSS 97%

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted …

Fix: 10.0.10240.19060 / 10.0.14393.4651+
Fix from $1,950 2021-09-15
Exchange Server HIGH 7.8
CVE-2021-27065 KEVEPSS 100%

Microsoft Exchange Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-03-03
Windows 10 HIGH 7.8
CVE-2020-1082

An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Ele…

Patch available
Fix from $1,950 2020-05-21
Codeql HIGH 7.8
CVE-2019-16765EPSS 5%

If an attacker can get a user to open a specially prepared directory tree as a workspace in Visual Studio Code with the CodeQL extension active, arbi…

Fix: 1.0.1+
Fix from $1,950 2019-11-25
.net Framework MEDIUM 5.5
CVE-2019-1142

An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka…

Patch available
Fix from $1,600 2019-09-11
Remote Desktop Client HIGH 8.0
CVE-2019-0887EPSS 71%

A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses…

Fix: 1.2.2691+
Fix from $1,950 2019-07-15
Windows 10 HIGH 7.5
CVE-2018-8495EPSS 51%

A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability." Thi…

Patch available
Fix from $1,950 2018-10-10
Windows 7 HIGH 7.8
CVE-2015-0016 KEVEPSS 76%

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 S…

Patch available
Fix from $1,950 2015-01-13
Sharepoint Foundation HIGH 7.5
CVE-2013-0084EPSS 21%

Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intend…

Mitigation only
Fix from $1,950 2013-03-13