Vulnerability index

Browse CVEs

38 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.8 CVE-2026-69278 Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Visual Studio Code 1.132.1+ Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-63512 Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-62872 Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. .net Framework No fix yet Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-62775 Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. Windows 11 26h1 10.0.28000.2704+ Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-61925 Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 8.2 CVE-2026-50528 Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. .net 8.0.29 / 9.0.18+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-47303 Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. .net 8.0.29 / 9.0.18+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-54998 Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. Exchange Online No fix yet Fix from $1,9502026-07-02 HIGH 7.8 CVE-2026-45490 Improper authorization in .NET allows an authorized attacker to elevate privileges locally. .net 8.0.28 / 9.0.17+ Fix from $1,9502026-06-09 CRITICAL 9.8 CVE-2026-33105 Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Azure Kubernetes Service Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-32213 Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. Azure Ai Foundry Mitigation only Fix from $2,3002026-04-03 HIGH 7.5 CVE-2026-32173 Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. Azure Sre Agent Mitigation only Fix from $1,9502026-04-03 HIGH 7.8 CVE-2026-26141 Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. Azure Automation Hybrid Worker Windows Extension 1.3.74+ Fix from $1,9502026-03-10 HIGH 8.0 CVE-2026-20960 Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. Power Apps 3.25121+ Fix from $1,9502026-01-16 HIGH 8.8 CVE-2025-29827 Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. Azure Automation Mitigation only Fix from $1,9502025-05-08 MEDIUM 6.4 CVE-2025-21403 On-Premises Data Gateway Information Disclosure Vulnerability On Prem Data Gateway 3000.246+ Fix from $1,6002025-01-14 MEDIUM 6.7 CVE-2023-24932EPSS 11% Secure Boot Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.19926 / 10.0.14393.5921+ Fix from $1,6002023-05-09 MEDIUM 6.8 CVE-2023-28270 Windows Lock Screen Security Feature Bypass Vulnerability Windows 10 1809 10.0.17763.4252 / 10.0.19042.2846+ Fix from $1,6002023-04-11 MEDIUM 6.8 CVE-2023-28249 Windows Boot Manager Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.19869 / 10.0.14393.5850+ Fix from $1,6002023-04-11 HIGH 7.3 CVE-2023-21715 KEVEPSS 12% Microsoft Publisher Security Feature Bypass Vulnerability 365 Apps Patch available Fix from $1,9502023-02-14 MEDIUM 6.5 CVE-2023-21719 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability Edge Chromium 109.0.1518.70+ Fix from $1,6002023-01-24 MEDIUM 6.6 CVE-2023-21560 Windows Boot Manager Security Feature Bypass Vulnerability Windows 10 1607 No fix yet Fix from $1,6002023-01-10 MEDIUM 5.3 CVE-2022-23551 aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI comp… Azure Ad Pod Identity 1.8.13+ Fix from $1,6002022-12-21 MEDIUM 5.4 CVE-2022-41091 KEV Windows Mark of the Web Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.19567 / 10.0.14393.5501+ Fix from $1,6002022-11-09 HIGH 7.4 CVE-2022-30203 Windows Boot Manager Security Feature Bypass Vulnerability Windows 10 Mitigation only Fix from $1,9502022-07-12 MEDIUM 5.3 CVE-2021-40456 Windows AD FS Security Feature Bypass Vulnerability Windows Server Patch available Fix from $1,6002021-10-13 CRITICAL 10.0 CVE-2021-37705 OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allow… Onefuzz 2.31.0+ Fix from $2,3002021-08-13 HIGH 8.8 CVE-2021-21552 Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicio… Windows 10 after 2019 Fix from $1,9502021-05-21 HIGH 7.8 CVE-2021-31165 Windows Container Manager Service Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-05-11 HIGH 7.8 CVE-2021-27086 Windows Services and Controller App Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-04-13