Vulnerability index

Browse CVEs

228 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.8 CVE-2026-21255 Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21238 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 CRITICAL 9.8 CVE-2026-24300 Azure Front Door Elevation of Privilege Vulnerability Azure Front Door No fix yet Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2026-24302 Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. Azure Arc Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.9 CVE-2026-24304 Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. Azure Resource Manager Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-24306 Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. Azure Front Door No fix yet Fix from $2,3002026-01-22 HIGH 7.8 CVE-2026-20949 Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. 365 Apps No fix yet Fix from $1,9502026-01-13 HIGH 7.5 CVE-2026-20929 Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20843 Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 MEDIUM 5.5 CVE-2026-20839 Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 HIGH 7.5 CVE-2026-0386 Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. Windows Server 2008 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2025-64669 Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally. Windows Admin Center 2511+ Fix from $1,9502025-12-11 HIGH 7.8 CVE-2025-64673 Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8146 / 10.0.19044.6691+ Fix from $1,9502025-12-09 MEDIUM 5.5 CVE-2025-62570 Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally. Windows 11 24h2 10.0.26100.7392 / 10.0.26200.7392+ Fix from $1,6002025-12-09 HIGH 7.8 CVE-2025-62474 Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8688 / 10.0.17763.8146+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-59517 Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8688 / 10.0.17763.8146+ Fix from $1,9502025-12-09 HIGH 8.0 CVE-2025-64660 Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. Visual Studio Code 1.106.2+ Fix from $1,9502025-11-20 HIGH 7.8 CVE-2025-60705 Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-59512 Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 MEDIUM 6.7 CVE-2025-47179 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. Configuration Manager 2403 5.00.9128.1037 / 5.00.9132.1031+ Fix from $1,6002025-11-11 HIGH 8.8 CVE-2025-59500 Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network. Azure Notification Service Mitigation only Fix from $1,9502025-10-23 CRITICAL 9.8 CVE-2025-59273 Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network. Azure Event Grid No fix yet Fix from $2,3002025-10-23 HIGH 7.8 CVE-2025-59494 Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. Azure Monitor Agent 1.38.1+ Fix from $1,9502025-10-14 MEDIUM 5.5 CVE-2025-59253 Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 HIGH 7.8 CVE-2025-59230 KEV Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59199 Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.7919 / 10.0.19044.6456+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59201 Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.5 CVE-2025-58726 Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-58724 Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. Azure Connected Machine Agent 1.57+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-58714 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14