Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Azure Cyclecloud HIGH 8.8
CVE-2026-70340

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $4,900 2026-08-11
Azure Cyclecloud MEDIUM 6.5
CVE-2026-65806

Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $4,000 2026-08-11
Exchange Server MEDIUM 6.5
CVE-2026-62915

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

Fix: 15.02.2562.046+
Fix from $4,000 2026-08-11
Windows 10 1809 MEDIUM 5.5
CVE-2026-61936

Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,000 2026-08-11
Visual Studio Code HIGH 8.8
CVE-2026-59113

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $4,900 2026-08-11
Dynamics 365 Business Central 2024 MEDIUM 6.5
CVE-2026-40375

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

Fix: 26.0.50788 / 27.0.50789+
Fix from $4,000 2026-08-11
Teams CRITICAL 10.0
CVE-2026-65667

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Azure Sre Agent CRITICAL 9.9
CVE-2026-62830

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-08-07
Edge Chromium HIGH 8.8
CVE-2026-66326

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 151.0.4129.59+
Fix from $1,950 2026-08-04
Edge Chromium MEDIUM 6.2
CVE-2026-66311

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

Fix: 151.0.4129.59+
Fix from $1,600 2026-08-04
Azure Dns CRITICAL 9.8
CVE-2026-58275

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Sharepoint Server HIGH 8.8
CVE-2026-55052

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20434+
Fix from $1,950 2026-07-14
Azure Cyclecloud MEDIUM 6.5
CVE-2026-58279

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

Fix: 8.9.1+
Fix from $1,600 2026-07-14
Exchange Online CRITICAL 9.6
CVE-2026-48582

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-06-19
Visual Studio Code CRITICAL 9.6
CVE-2026-47281

Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Fix: 1.123.1+
Fix from $2,300 2026-06-09
Windows Admin Center HIGH 8.3
CVE-2026-35438

Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 2511+
Fix from $1,950 2026-05-12
Nuance Powerscribe 360 HIGH 8.1
CVE-2025-30398

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2025-11-11
Windows Server 2022 CRITICAL 9.1
CVE-2025-50171

Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.20348.3989 / 10.0.25398.1791+
Fix from $2,300 2025-08-12
Azure Machine Learning HIGH 8.8
CVE-2025-49747

Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-07-18
Windows 10 1809 HIGH 8.8
CVE-2025-49723

Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.

Fix: 10.0.17763.7558 / 10.0.19044.6093+
Fix from $1,950 2025-07-08
Azure Virtual Desktop HIGH 8.8
CVE-2025-21416

Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-04-30
Account HIGH 8.2
CVE-2025-21396

Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2025-01-29
Power Platform HIGH 8.6
CVE-2024-38190

Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.

Patch available
Fix from $1,950 2024-10-15
Azure Stack Hci HIGH 8.8
CVE-2024-38179

Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2024-10-08
Windows 10 1809 HIGH 8.8
CVE-2024-21417

Windows Text Services Framework Elevation of Privilege Vulnerability

Fix: 10.0.17763.6054 / 10.0.19044.4651+
Fix from $1,950 2024-07-10
Windows 10 MEDIUM 5.5
CVE-2020-0989

<p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker w…

Patch available
Fix from $1,600 2020-09-11
Windows 10 HIGH 7.9
CVE-2019-1170

An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. An attacker who succes…

Patch available
Fix from $1,950 2019-08-14
Edge HIGH 8.8
CVE-2019-0566EPSS 19%

An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability.…

Patch available
Fix from $1,950 2019-01-08
Windows 10 HIGH 7.8
CVE-2019-0555

An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbo…

Patch available
Fix from $1,950 2019-01-08
Windows 10 HIGH 7.8
CVE-2019-0573EPSS 20%

An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Se…

Patch available
Fix from $1,950 2019-01-08