Vulnerability index

Browse CVEs

73 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 8.8 CVE-2026-62827 Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 CRITICAL 9.6 CVE-2026-62896 Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. Teams No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-56162 Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. Azure Sql Database No fix yet Fix from $2,3002026-08-07 CRITICAL 9.8 CVE-2026-62825 Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. Azure Key Vault No fix yet Fix from $2,3002026-07-24 CRITICAL 10.0 CVE-2026-56191 Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. Exchange Online No fix yet Fix from $2,3002026-07-24 HIGH 8.0 CVE-2026-50365 Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-56169 Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. Windows Admin Center 2606+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-57107 Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. Windows Admin Center 2606+ Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-56185 Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. Windows Admin Center 2511+ Fix from $1,6002026-07-14 HIGH 8.2 CVE-2026-50338 Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network. Azure Spring Cloud 7.3.0+ Fix from $1,9502026-07-14 CRITICAL 10.0 CVE-2026-45480 Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. Azure Active Directory No fix yet Fix from $2,3002026-06-19 HIGH 8.8 CVE-2026-32174 Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. Azure Ai Bot Service Mitigation only Fix from $1,9502026-06-18 HIGH 7.8 CVE-2026-44810 Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally. Windows 11 23h2 10.0.20348.5256 / 10.0.22631.7219+ Fix from $1,9502026-06-09 CRITICAL 9.8 CVE-2026-47280 Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. Azure Resource Manager No fix yet Fix from $2,3002026-05-22 CRITICAL 10.0 CVE-2026-42822 Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. Azure Local 2604.2.25645+ Fix from $2,3002026-05-18 CRITICAL 9.1 CVE-2026-33117 The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com… Azure Sdk For Java 4.10.6+ Fix from $2,3002026-05-12 MEDIUM 6.2 CVE-2026-32072 Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 HIGH 7.5 CVE-2026-32173 Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. Azure Sre Agent Mitigation only Fix from $1,9502026-04-03 HIGH 7.8 CVE-2026-26141 Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. Azure Automation Hybrid Worker Windows Extension 1.3.74+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26128 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-24294 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-26119 Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. Windows Admin Center 2511+ Fix from $1,9502026-02-17 HIGH 7.0 CVE-2026-21508 Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2025-55340 Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally. Windows 10 21h2 10.0.19044.6456 / 10.0.19045.6456+ Fix from $1,9502025-10-14 CRITICAL 9.8 CVE-2025-55234EPSS 20% SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could p… Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $2,3002025-09-09 HIGH 8.8 CVE-2025-54918EPSS 19% Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. Windows 10 1507 10.0.10240.21128 / 10.0.14393.8422+ Fix from $1,9502025-09-09 CRITICAL 10.0 CVE-2025-55241 Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002025-09-04 HIGH 7.5 CVE-2025-53793 Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network. Azure Stack Hub 1.2406.1.23 / 1.2408.1.50+ Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-53778EPSS 38% Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 HIGH 8.0 CVE-2025-53786EPSS 7% On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made… Exchange Server 15.02.2562.017+ Fix from $1,9502025-08-06