Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Windows 10 1607 HIGH 8.8
CVE-2026-21255

Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.8
CVE-2026-21238

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Azure Front Door CRITICAL 9.8
CVE-2026-24300

Azure Front Door Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-02-05
Azure Arc CRITICAL 9.8
CVE-2026-24302

Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-02-05
Azure Resource Manager CRITICAL 9.9
CVE-2026-24304

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-01-23
Azure Front Door CRITICAL 9.8
CVE-2026-24306

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-01-22
365 Apps HIGH 7.8
CVE-2026-20949

Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

No fix yet
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.5
CVE-2026-20929

Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.8
CVE-2026-20843

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 MEDIUM 5.5
CVE-2026-20839

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Windows Server 2008 HIGH 7.5
CVE-2026-0386

Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows Admin Center HIGH 7.8
CVE-2025-64669

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.

Fix: 2511+
Fix from $1,950 2025-12-11
Windows 10 1809 HIGH 7.8
CVE-2025-64673

Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 11 24h2 MEDIUM 5.5
CVE-2025-62570

Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.

Fix: 10.0.26100.7392 / 10.0.26200.7392+
Fix from $1,600 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-62474

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-59517

Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Visual Studio Code HIGH 8.0
CVE-2025-64660

Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.

Fix: 1.106.2+
Fix from $1,950 2025-11-20
Windows 10 1607 HIGH 7.8
CVE-2025-60705

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.8
CVE-2025-59512

Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Configuration Manager 2403 MEDIUM 6.7
CVE-2025-47179

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.

Fix: 5.00.9128.1037 / 5.00.9132.1031+
Fix from $1,600 2025-11-11
Azure Notification Service HIGH 8.8
CVE-2025-59500

Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-10-23
Azure Event Grid CRITICAL 9.8
CVE-2025-59273

Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-10-23
Azure Monitor Agent HIGH 7.8
CVE-2025-59494

Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.38.1+
Fix from $1,950 2025-10-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-59253

Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-59230 KEV

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1809 HIGH 7.8
CVE-2025-59199

Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7919 / 10.0.19044.6456+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-59201

Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.5
CVE-2025-58726

Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Azure Connected Machine Agent HIGH 7.8
CVE-2025-58724

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.57+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-58714

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14