Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
365 Copilot CRITICAL 9.3
CVE-2026-41106

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-07-02
365 Copilot HIGH 8.8
CVE-2026-47645

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges ov…

Mitigation only
Fix from $1,950 2026-06-19
365 Copilot CRITICAL 9.3
CVE-2026-33102

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-23
Windows 10 1809 MEDIUM 6.8
CVE-2024-43543

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Fix: 10.0.17763.6414 / 10.0.19044.5011+
Fix from $1,600 2024-10-08
Windows 10 1809 MEDIUM 6.8
CVE-2024-43536

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Fix: 10.0.17763.6414 / 10.0.19044.5011+
Fix from $1,600 2024-10-08
Dynamics 365 HIGH 8.2
CVE-2024-38211

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Patch available
Fix from $1,950 2024-08-13
Edge Chromium MEDIUM 6.1
CVE-2023-24935

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Fix: 112.0.5615.49+
Fix from $1,600 2023-04-11
Edge Chromium HIGH 8.2
CVE-2023-24892

Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability

Fix: 111.0.1661.41+
Fix from $1,950 2023-03-14
Sharepoint Enterprise Server MEDIUM 6.1
CVE-2020-1323

An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link…

Patch available
Fix from $1,600 2020-06-09
Edge MEDIUM 6.1
CVE-2020-1220

A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromi…

Patch available
Fix from $1,600 2020-06-09
Visual Studio 2019 MEDIUM 6.1
CVE-2019-1486

A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specifie…

Fix: 1.0.1374+
Fix from $1,600 2019-12-10
Asp.net Core MEDIUM 6.1
CVE-2019-1075

A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.

Patch available
Fix from $1,600 2019-07-15
Excel Viewer MEDIUM 5.5
CVE-2019-0540EPSS 13%

A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file,…

Patch available
Fix from $1,600 2019-03-05
Exchange Server MEDIUM 6.5
CVE-2018-0924EPSS 8%

Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 C…

Patch available
Fix from $1,600 2018-03-14
Asp.net Core HIGH 8.8
CVE-2017-11879EPSS 9%

ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP…

Patch available
Fix from $1,950 2017-11-15
Exchange Server MEDIUM 6.1
CVE-2017-8621

Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnera…

Patch available
Fix from $1,600 2017-07-11
Exchange Server MEDIUM 5.8
CVE-2005-0420EPSS 26%

Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the …

No fix yet
Fix from $1,600 2005-04-27