Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Windows 10 22h2 HIGH 7.8
CVE-2026-66804

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19045.7663 / 10.0.26100.9106+
Fix from $4,900 2026-08-11
Windows 10 1809 HIGH 7.8
CVE-2026-65773

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,900 2026-08-11
Github Copilot Chat MEDIUM 6.5
CVE-2026-65675

No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.

No fix yet
Fix from $4,000 2026-08-11
Purview Ediscovery HIGH 8.8
CVE-2026-65668

Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-08-07
Azure Logic Apps CRITICAL 9.6
CVE-2026-56161

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $2,300 2026-08-07
Azure Cosmos Db CRITICAL 10.0
CVE-2026-66803

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-30
Azure App Service For Linux CRITICAL 9.8
CVE-2026-58630

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Azure Api Management HIGH 7.2
CVE-2026-35425

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2026-07-24
Configuration Manager 2503 HIGH 8.8
CVE-2026-47301

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-07-14
365 Copilot CRITICAL 9.8
CVE-2026-58617

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

Fix: 2.111.4+
Fix from $2,300 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-58545

Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-57088

Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.20348.5386+
Fix from $1,950 2026-07-14
Sharepoint Server MEDIUM 5.4
CVE-2026-56157

Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20434+
Fix from $1,600 2026-07-14
Windows 10 1809 MEDIUM 5.5
CVE-2026-50495

Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,600 2026-07-14
Windows 11 24h2 HIGH 7.1
CVE-2026-50465

Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 10 21h2 HIGH 7.8
CVE-2026-50423

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7548 / 10.0.19045.7548+
Fix from $1,950 2026-07-14
Windows 11 24h2 MEDIUM 6.1
CVE-2026-50418

Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.

Fix: 10.0.20348.5386 / 10.0.26100.8875+
Fix from $1,600 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-50373

Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-50335

Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Remote Help HIGH 7.8
CVE-2026-55014

Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.

Fix: 5.2.1037.0+
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 8.8
CVE-2026-50342

Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8875 / 10.0.26200.8875+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-50351

Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-50311

Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.0
CVE-2026-50325

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.0
CVE-2026-50297

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.0
CVE-2026-49805

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Edge Chromium HIGH 8.2
CVE-2026-58525

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Fix: 150.0.4078.50+
Fix from $1,950 2026-07-08
Edge Chromium MEDIUM 6.5
CVE-2026-58523

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Edge Chromium MEDIUM 6.9
CVE-2026-58286

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Edge Chromium MEDIUM 6.9
CVE-2026-58282

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03