Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Sharepoint Server MEDIUM 5.4
CVE-2026-47634

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorize…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Teams HIGH 8.1
CVE-2026-42835

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorize…

Fix: 1.0.76.2026111302+
Fix from $1,950 2026-06-09
Copilot Chat HIGH 7.5
CVE-2026-47644

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unautho…

Mitigation only
Fix from $1,950 2026-06-04
Edge Chromium MEDIUM 5.4
CVE-2026-42838

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unaut…

Fix: 148.0.3967.55+
Fix from $1,600 2026-05-12
Visual Studio Code HIGH 8.8
CVE-2026-41109

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unau…

Fix: 1.119.1+
Fix from $1,950 2026-05-12
Azure Machine Learning HIGH 8.2
CVE-2026-33833

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized a…

Mitigation only
Fix from $1,950 2026-05-12
365 Copilot Chat HIGH 7.5
CVE-2026-26164

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…

No fix yet
Fix from $1,950 2026-05-07
365 Copilot HIGH 7.5
CVE-2025-32711EPSS 8%

Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $1,950 2025-06-11
Azure Sphere HIGH 7.8
CVE-2020-35608

A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted …

No fix yet
Fix from $1,950 2020-12-22
Exchange Server HIGH 8.4
CVE-2020-16875EPSS 47%

<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who s…

Patch available
Fix from $1,950 2020-09-11
Skype For Business MEDIUM 5.4
CVE-2019-1490

A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Serv…

Patch available
Fix from $1,600 2019-12-10
Sql Server HIGH 7.1
CVE-2015-1762EPSS 10%

Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014, when transactional replication is configured, does not preven…

Mitigation only
Fix from $1,950 2015-07-14