Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Azure Synapse CRITICAL 9.8
CVE-2026-26145

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-02
Dynamics 365 CRITICAL 9.9
CVE-2026-47647

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-06-18
Pc Manager HIGH 7.8
CVE-2026-49161

Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.

Fix: 3.21.6.0+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.9
CVE-2026-48578

Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 MEDIUM 6.8
CVE-2026-45658

Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 11 24h2 HIGH 7.9
CVE-2026-45654

Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.26100.8655 / 10.0.26100.32995+
Fix from $1,950 2026-06-09
Excel HIGH 7.1
CVE-2026-45649

Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.

No fix yet
Fix from $1,950 2026-06-09
Windows 11 24h2 HIGH 7.8
CVE-2026-42829

Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.26100.8655 / 10.0.26200.8655+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-41092

Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Azure Logic Apps CRITICAL 9.9
CVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-12
Excel MEDIUM 5.5
CVE-2026-42832

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

Fix: 16.0.19822.20190+
Fix from $1,600 2026-05-12
365 Copilot MEDIUM 6.2
CVE-2026-41614

Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.

Fix: 19.2604.43111.0+
Fix from $1,600 2026-05-12
Word MEDIUM 5.5
CVE-2026-41101

Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.

Fix: 16.0.19822.20190+
Fix from $1,600 2026-05-12
Powerpoint MEDIUM 5.5
CVE-2026-41102

Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.

Fix: 16.0.19822.20190+
Fix from $1,600 2026-05-12
365 Apps HIGH 8.8
CVE-2026-40420

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-05-12
Windows Admin Center HIGH 8.8
CVE-2026-41086

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 2.6.7+
Fix from $1,950 2026-05-12
Azure Connected Machine Agent HIGH 7.8
CVE-2026-40381

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.63+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-33834

Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Azure Ai Foundry CRITICAL 10.0
CVE-2026-35435

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-07
Azure Managed Instance For Apache Cassandra CRITICAL 9.9
CVE-2026-33109

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-05-07
Partner Center CRITICAL 9.6
CVE-2026-24303

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-23
Dynamics 365 MEDIUM 5.5
CVE-2026-33103

Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.

Fix: 9.1.44.15+
Fix from $1,600 2026-04-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-32214

Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-27914

Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows Server 2012 HIGH 7.8
CVE-2026-26183

Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-25176

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1809 HIGH 7.8
CVE-2026-24290

Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8511 / 10.0.19044.7058+
Fix from $1,950 2026-03-10
Windows Admin Center HIGH 7.8
CVE-2026-23660

Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.

Fix: 2.6.4+
Fix from $1,950 2026-03-10
Sql Server 2016 HIGH 8.8
CVE-2026-21262

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Fix: 13.0.6480.4 / 13.0.7075.5+
Fix from $1,950 2026-03-10
Teams HIGH 7.5
CVE-2026-21535

Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-02-19