Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.8 CVE-2026-63522 Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. Azure Sql Database No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-24291 Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate… Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2025-21325 Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows 10 21h2 10.0.19044.5371 / 10.0.19045.5371+ Fix from $1,9502025-01-17 MEDIUM 6.7 CVE-2024-21431 Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability Windows 10 21h2 10.0.19044.4170 / 10.0.19045.4170+ Fix from $1,6002024-03-12 HIGH 7.0 CVE-2023-23939 Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3. An insecure temporary creat… Azure Setup Kubectl 3.0+ Fix from $1,9502023-03-06 HIGH 8.8 CVE-2021-42309 Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Enterprise Server Patch available Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-26434 Visual Studio Elevation of Privilege Vulnerability Visual Studio 2017 after 16.11 Fix from $1,9502021-09-15 HIGH 7.8 CVE-2021-31167 Windows Container Manager Service Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-05-11 HIGH 7.3 CVE-2021-27070 Windows 10 Update Assistant Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-03-11 MEDIUM 6.2 CVE-2020-16990 Azure Sphere Information Disclosure Vulnerability Azure Sphere 20.07+ Fix from $1,6002020-11-11 HIGH 7.8 CVE-2020-1170 An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an … Windows Defender Patch available Fix from $1,9502020-06-09 HIGH 7.8 CVE-2020-0668EPSS 26% An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privile… Windows 10 Patch available Fix from $1,9502020-02-11 HIGH 7.8 CVE-2019-1457 A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Offi… Office Patch available Fix from $1,9502019-11-12 HIGH 7.8 CVE-2019-1378 An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker coul… Windows 10 Update Assistant Patch available Fix from $1,9502019-10-10 MEDIUM 6.5 CVE-2019-0804EPSS 5% An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent Information… Walinuxagent 2.2.38+ Fix from $1,6002019-04-09 MEDIUM 6.5 CVE-2019-0588 An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than int… Exchange Server Patch available Fix from $1,6002019-01-08 HIGH 7.8 CVE-2018-8411 An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Wind… Windows 10 Patch available Fix from $1,9502018-10-10 HIGH 7.0 CVE-2018-0982 An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulne… Windows 10 Patch available Fix from $1,9502018-06-14 HIGH 7.0 CVE-2018-1036 An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Wind… Windows 10 Mitigation only Fix from $1,9502018-06-14 HIGH 7.8 CVE-2018-0752 The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Win… Windows 10 Patch available Fix from $1,9502018-01-04 HIGH 7.8 CVE-2017-8665 The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege V… Xamarin.ios after 10.11 Fix from $1,9502017-08-15 MEDIUM 6.5 CVE-2010-0488EPSS 29% Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypas… Internet Explorer Patch available Fix from $1,6002010-03-31 HIGH 7.1 CVE-2001-0006 The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the … Windows Nt Patch available Fix from $1,9502001-02-12