Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
MEDIUM 5.4 CVE-2026-47634 Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorize… Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 HIGH 8.1 CVE-2026-42835 Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorize… Teams 1.0.76.2026111302+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-47644 Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unautho… Copilot Chat Mitigation only Fix from $1,9502026-06-04 MEDIUM 5.4 CVE-2026-42838 Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unaut… Edge Chromium 148.0.3967.55+ Fix from $1,6002026-05-12 HIGH 8.8 CVE-2026-41109 Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unau… Visual Studio Code 1.119.1+ Fix from $1,9502026-05-12 HIGH 8.2 CVE-2026-33833 Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized a… Azure Machine Learning Mitigation only Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-26164 Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor… 365 Copilot Chat No fix yet Fix from $1,9502026-05-07 HIGH 7.5 CVE-2025-32711EPSS 8% Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. 365 Copilot No fix yet Fix from $1,9502025-06-11 HIGH 7.8 CVE-2020-35608 A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted … Azure Sphere No fix yet Fix from $1,9502020-12-22 HIGH 8.4 CVE-2020-16875EPSS 47% <p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who s… Exchange Server Patch available Fix from $1,9502020-09-11 MEDIUM 5.4 CVE-2019-1490 A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Serv… Skype For Business Patch available Fix from $1,6002019-12-10 HIGH 7.1 CVE-2015-1762EPSS 10% Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014, when transactional replication is configured, does not preven… Sql Server Mitigation only Fix from $1,9502015-07-14