Vulnerability index

Browse CVEs

38 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Visual Studio Code HIGH 7.8
CVE-2026-69278

Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Fix: 1.132.1+
Fix from $4,900 2026-08-11
Sharepoint Server MEDIUM 6.5
CVE-2026-63512

Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
.net Framework HIGH 8.8
CVE-2026-62872

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $4,900 2026-08-11
Windows 11 26h1 MEDIUM 5.5
CVE-2026-62775

Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

Fix: 10.0.28000.2704+
Fix from $4,000 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-61925

Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11
.net HIGH 8.2
CVE-2026-50528

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

Fix: 8.0.29 / 9.0.18+
Fix from $1,950 2026-07-14
.net HIGH 8.8
CVE-2026-47303

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

Fix: 8.0.29 / 9.0.18+
Fix from $1,950 2026-07-14
Exchange Online HIGH 8.8
CVE-2026-54998

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-07-02
.net HIGH 7.8
CVE-2026-45490

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

Fix: 8.0.28 / 9.0.17+
Fix from $1,950 2026-06-09
Azure Kubernetes Service CRITICAL 9.8
CVE-2026-33105

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Ai Foundry CRITICAL 9.8
CVE-2026-32213

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Sre Agent HIGH 7.5
CVE-2026-32173

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-04-03
Azure Automation Hybrid Worker Windows Extension HIGH 7.8
CVE-2026-26141

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

Fix: 1.3.74+
Fix from $1,950 2026-03-10
Power Apps HIGH 8.0
CVE-2026-20960

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

Fix: 3.25121+
Fix from $1,950 2026-01-16
Azure Automation HIGH 8.8
CVE-2025-29827

Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-05-08
On Prem Data Gateway MEDIUM 6.4
CVE-2025-21403

On-Premises Data Gateway Information Disclosure Vulnerability

Fix: 3000.246+
Fix from $1,600 2025-01-14
Windows 10 1507 MEDIUM 6.7
CVE-2023-24932EPSS 11%

Secure Boot Security Feature Bypass Vulnerability

Fix: 10.0.10240.19926 / 10.0.14393.5921+
Fix from $1,600 2023-05-09
Windows 10 1809 MEDIUM 6.8
CVE-2023-28270

Windows Lock Screen Security Feature Bypass Vulnerability

Fix: 10.0.17763.4252 / 10.0.19042.2846+
Fix from $1,600 2023-04-11
Windows 10 1507 MEDIUM 6.8
CVE-2023-28249

Windows Boot Manager Security Feature Bypass Vulnerability

Fix: 10.0.10240.19869 / 10.0.14393.5850+
Fix from $1,600 2023-04-11
365 Apps HIGH 7.3
CVE-2023-21715 KEVEPSS 12%

Microsoft Publisher Security Feature Bypass Vulnerability

Patch available
Fix from $1,950 2023-02-14
Edge Chromium MEDIUM 6.5
CVE-2023-21719

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Fix: 109.0.1518.70+
Fix from $1,600 2023-01-24
Windows 10 1607 MEDIUM 6.6
CVE-2023-21560

Windows Boot Manager Security Feature Bypass Vulnerability

No fix yet
Fix from $1,600 2023-01-10
Azure Ad Pod Identity MEDIUM 5.3
CVE-2022-23551

aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI comp…

Fix: 1.8.13+
Fix from $1,600 2022-12-21
Windows 10 1507 MEDIUM 5.4
CVE-2022-41091 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

Fix: 10.0.10240.19567 / 10.0.14393.5501+
Fix from $1,600 2022-11-09
Windows 10 HIGH 7.4
CVE-2022-30203

Windows Boot Manager Security Feature Bypass Vulnerability

Mitigation only
Fix from $1,950 2022-07-12
Windows Server MEDIUM 5.3
CVE-2021-40456

Windows AD FS Security Feature Bypass Vulnerability

Patch available
Fix from $1,600 2021-10-13
Onefuzz CRITICAL 10.0
CVE-2021-37705

OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allow…

Fix: 2.31.0+
Fix from $2,300 2021-08-13
Windows 10 HIGH 8.8
CVE-2021-21552

Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicio…

Fix: after 2019
Fix from $1,950 2021-05-21
Windows 10 HIGH 7.8
CVE-2021-31165

Windows Container Manager Service Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-05-11
Windows 10 HIGH 7.8
CVE-2021-27086

Windows Services and Controller App Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-04-13