Vulnerability index

Browse CVEs

356 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Edge Chromium MEDIUM 5.4
CVE-2026-32208

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform s…

Mitigation only
Fix from $1,600 2026-06-19
Sharepoint Server MEDIUM 5.4
CVE-2026-48560

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47640

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47634

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorize…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47636

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47639

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Exchange Server MEDIUM 5.4
CVE-2026-47631

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47637

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47638

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Live Share Canvas HIGH 8.0
CVE-2026-45644

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker…

Fix: 1.4.2+
Fix from $1,950 2026-06-09
Exchange Server MEDIUM 6.1
CVE-2026-45501

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
Exchange Server MEDIUM 6.1
CVE-2026-45500

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45479

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45481

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45483

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45467

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45468

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45464

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45465

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45462

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-45453

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Azure Stack Edge HIGH 8.4
CVE-2026-41098

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spo…

Fix: 3.3.2604.3097+
Fix from $1,950 2026-06-09
Sharepoint Server MEDIUM 6.1
CVE-2026-33113

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Edge Chromium MEDIUM 6.1
CVE-2026-45494

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Fix: 148.0.3967.70+
Fix from $1,600 2026-05-18
Exchange Server MEDIUM 6.1
CVE-2026-42897 KEVEPSS 70%

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …

Fix: 15.02.2562.043+
Fix from $1,600 2026-05-14
Visual Studio Code MEDIUM 5.0
CVE-2026-41610

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass …

Fix: 1.119.1+
Fix from $1,600 2026-05-12
Azure Machine Learning MEDIUM 6.1
CVE-2026-32207

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to per…

Mitigation only
Fix from $1,600 2026-05-07
Windows Admin Center MEDIUM 6.1
CVE-2026-32196

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perfo…

Fix: 2511+
Fix from $1,600 2026-04-14
Sharepoint Server MEDIUM 5.4
CVE-2026-20945EPSS 25%

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20210+
Fix from $1,600 2026-04-14
Sharepoint Server CRITICAL 9.3
CVE-2026-26105

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20076+
Fix from $2,300 2026-03-10