Vulnerability index

Browse CVEs

40 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
HIGH 8.8 CVE-2026-64921 Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-62777 Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61367 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61364 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61365 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61356 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,9002026-08-11 CRITICAL 9.4 CVE-2026-50516 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo… Azure Kubernetes Service No fix yet Fix from $5,7502026-08-11 HIGH 7.8 CVE-2026-42976 Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 CRITICAL 10.0 CVE-2026-63508 Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. Planetary Computer No fix yet Fix from $2,3002026-08-07 CRITICAL 10.0 CVE-2026-56163 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo… Azure Kubernetes Service No fix yet Fix from $2,3002026-07-24 HIGH 7.8 CVE-2026-50451 Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges … Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-50444 Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-57969 Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. Azure Cyclecloud 8.9.1+ Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-56164 KEVEPSS 22% Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 HIGH 7.8 CVE-2026-50333 Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 6.1 CVE-2026-49174 Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-54130 Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. 365 Copilot Mitigation only Fix from $1,9502026-06-18 HIGH 7.8 CVE-2026-50512 Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.21.6.0+ Fix from $1,9502026-06-09 MEDIUM 6.8 CVE-2026-50507EPSS 5% Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,6002026-06-09 CRITICAL 9.6 CVE-2026-47281 Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. Visual Studio Code 1.123.1+ Fix from $2,3002026-06-09 HIGH 7.8 CVE-2026-26159 Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-26160 Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 HIGH 7.5 CVE-2026-32211 Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network. Azure Web Apps Mitigation only Fix from $1,9502026-04-03 HIGH 7.5 CVE-2026-23662 Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. Azure Iot Explorer 0.15.13+ Fix from $1,9502026-03-10 CRITICAL 9.8 CVE-2026-26125 Payment Orchestrator Service Elevation of Privilege Vulnerability Payment Orchestrator Service No fix yet Fix from $2,3002026-03-05 HIGH 7.2 CVE-2026-20803 Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network. Sql Server 2022 16.0.1165.1 / 16.0.4230.2+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2025-59516 Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8146 / 10.0.19044.6691+ Fix from $1,9502025-12-09 CRITICAL 9.8 CVE-2025-59246EPSS 7% Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002025-10-09 HIGH 7.8 CVE-2025-53789 Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-08-12 HIGH 7.5 CVE-2025-48814 Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature… Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08