Vulnerability index

Browse CVEs

356 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Azure Hdinsight MEDIUM 5.4
CVE-2026-21529

Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spo…

Fix: 5.1+
Fix from $1,600 2026-02-10
Account MEDIUM 6.1
CVE-2026-21264

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform …

Mitigation only
Fix from $1,600 2026-01-22
Sharepoint Server MEDIUM 5.4
CVE-2026-20959EPSS 7%

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19127.20442+
Fix from $1,600 2026-01-13
Azure Cosmos Db CRITICAL 9.6
CVE-2025-64675

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform sp…

Mitigation only
Fix from $2,300 2025-12-19
Office Out Of Box Experience HIGH 8.2
CVE-2025-64677

Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker …

Mitigation only
Fix from $1,950 2025-12-18
Sharepoint Server CRITICAL 9.0
CVE-2025-64672

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19127.20378+
Fix from $2,300 2025-12-09
365 Defender Portal MEDIUM 6.1
CVE-2025-62459

Microsoft Defender Portal Spoofing Vulnerability

No fix yet
Fix from $1,600 2025-11-20
Dynamics 365 HIGH 8.7
CVE-2025-62210

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized atta…

Fix: 8.8.139.398+
Fix from $1,950 2025-11-11
Dynamics 365 HIGH 8.7
CVE-2025-62211

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized atta…

Fix: 8.8.139.398+
Fix from $1,950 2025-11-11
Azure Monitor CRITICAL 9.3
CVE-2025-55321

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoo…

Mitigation only
Fix from $2,300 2025-10-09
Dynamics 365 MEDIUM 5.4
CVE-2025-49745

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized a…

Fix: 9.1.38.10+
Fix from $1,600 2025-08-12
Nuance Digital Engagement Platform HIGH 8.2
CVE-2025-47977

Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized att…

Fix: 5.64.x+
Fix from $1,950 2025-06-10
Sharepoint Server MEDIUM 6.3
CVE-2025-21393

Microsoft SharePoint Server Spoofing Vulnerability

Fix: 16.0.17928.20356+
Fix from $1,600 2025-01-14
Nugetgallery MEDIUM 6.1
CVE-2024-54138

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Ma…

Fix: 2024.12.06+
Fix from $1,600 2024-12-06
Dynamics 365 Sales HIGH 7.6
CVE-2024-49053

Microsoft Dynamics 365 Sales Spoofing Vulnerability

Fix: 3.24104.15+
Fix from $1,950 2024-11-26
Copilot Studio CRITICAL 9.6
CVE-2024-49038

Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation…

Mitigation only
Fix from $2,300 2024-11-26
Windows 10 1507 HIGH 8.1
CVE-2024-43573 KEVEPSS 44%

Windows MSHTML Platform Spoofing Vulnerability

Fix: 10.0.10240.20796 / 10.0.14393.7428+
Fix from $1,950 2024-10-08
Power Bi Report Server HIGH 8.8
CVE-2024-43481

Power BI Report Server Spoofing Vulnerability

Fix: 15.0.1116.121+
Fix from $1,950 2024-10-08
Nugetgallery MEDIUM 6.1
CVE-2024-47604

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes…

Fix: 2024.09.25+
Fix from $1,600 2024-10-01
Dynamics 365 MEDIUM 5.4
CVE-2024-43476

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Fix: 9.1.32+
Fix from $1,600 2024-09-10
Edge MEDIUM 6.1
CVE-2024-38208

Microsoft Edge for Android Spoofing Vulnerability

Fix: 128.0.2739.42+
Fix from $1,600 2024-08-22
Dynamics 365 HIGH 8.2
CVE-2024-38211

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Patch available
Fix from $1,950 2024-08-13
Azure Stack Hub CRITICAL 9.3
CVE-2024-38108

Azure Stack Hub Spoofing Vulnerability

Fix: 1.2311.1.22+
Fix from $2,300 2024-08-13
Dynamics Crm Service Portal Web Resource MEDIUM 6.1
CVE-2024-38166

An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network…

Patch available
Fix from $1,600 2024-08-06
Edge MEDIUM 6.1
CVE-2024-38156

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Fix: 126.0.2592.102+
Fix from $1,600 2024-07-19
Azure Devops Server HIGH 7.6
CVE-2024-35266

Azure DevOps Server Spoofing Vulnerability

Patch available
Fix from $1,950 2024-07-09
Azure Devops Server HIGH 7.6
CVE-2024-35267

Azure DevOps Server Spoofing Vulnerability

Patch available
Fix from $1,950 2024-07-09
Nugetgallery MEDIUM 6.1
CVE-2024-37304

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Ma…

Fix: 2024.05.28+
Fix from $1,600 2024-06-12
Azure Migrate MEDIUM 5.4
CVE-2024-30053

Azure Migrate Cross-Site Scripting Vulnerability

Fix: 6.1.294.1008+
Fix from $1,600 2024-05-14
Dynamics 365 MEDIUM 5.4
CVE-2024-21419

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Fix: 9.1.26+
Fix from $1,600 2024-03-12