Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.8 CVE-2026-66804 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. Windows 10 22h2 10.0.19045.7663 / 10.0.26100.9106+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-65773 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-65675 No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. Github Copilot Chat No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-65668 Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. Purview Ediscovery No fix yet Fix from $1,9502026-08-07 CRITICAL 9.6 CVE-2026-56161 Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. Azure Logic Apps No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-66803 Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. Azure Cosmos Db No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-58630 Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. Azure App Service For Linux No fix yet Fix from $2,3002026-07-24 HIGH 7.2 CVE-2026-35425 Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. Azure Api Management No fix yet Fix from $1,9502026-07-24 HIGH 8.8 CVE-2026-47301 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. Configuration Manager 2503 Mitigation only Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-58617 Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. 365 Copilot 2.111.4+ Fix from $2,3002026-07-14 MEDIUM 5.5 CVE-2026-58545 Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-57088 Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9020 / 10.0.20348.5386+ Fix from $1,9502026-07-14 MEDIUM 5.4 CVE-2026-56157 Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20434+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-50495 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,6002026-07-14 HIGH 7.1 CVE-2026-50465 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. Windows 11 24h2 10.0.26100.8875 / 10.0.26100.33158+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50423 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.7548 / 10.0.19045.7548+ Fix from $1,9502026-07-14 MEDIUM 6.1 CVE-2026-50418 Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. Windows 11 24h2 10.0.20348.5386 / 10.0.26100.8875+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-50373 Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50335 Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-55014 Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally. Remote Help 5.2.1037.0+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-50342 Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.8875 / 10.0.26200.8875+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50351 Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50311 Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.0 CVE-2026-50325 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.0 CVE-2026-50297 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.0 CVE-2026-49805 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.2 CVE-2026-58525 Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. Edge Chromium 150.0.4078.50+ Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-58523 Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. Edge Chromium 150.0.4078.48+ Fix from $1,6002026-07-03 MEDIUM 6.9 CVE-2026-58286 Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Edge Chromium 150.0.4078.48+ Fix from $1,6002026-07-03 MEDIUM 6.9 CVE-2026-58282 Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Edge Chromium 150.0.4078.48+ Fix from $1,6002026-07-03