Vulnerability index

Browse CVEs

312 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Visual Studio Code HIGH 8.8
CVE-2026-70336

Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

Fix: 1.132.1+
Fix from $4,900 2026-08-11
Powershell HIGH 7.8
CVE-2026-70338

Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locall…

Fix: 7.4.19.0 / 7.5.10.0+
Fix from $4,900 2026-08-11
Sharepoint Server MEDIUM 6.5
CVE-2026-65660

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a net…

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
Edge Chromium MEDIUM 6.1
CVE-2026-65804

Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over…

Fix: 151.0.4129.59+
Fix from $1,600 2026-08-04
.net Framework HIGH 7.8
CVE-2026-50650

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

Fix: 8.0.29 / 9.0.18+
Fix from $1,950 2026-07-14
Windows Admin Center MEDIUM 6.5
CVE-2026-56185

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

Fix: 2511+
Fix from $1,600 2026-07-14
Visual Studio Code HIGH 7.8
CVE-2026-47292

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

Fix: 1.123.1+
Fix from $1,950 2026-06-09
Exchange Server HIGH 8.1
CVE-2026-45583

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

Fix: 15.02.2562.043+
Fix from $1,950 2026-06-09
Edge Chromium CRITICAL 9.8
CVE-2026-45495

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 148.0.3967.70+
Fix from $2,300 2026-05-18
Dynamics 365 CRITICAL 9.9
CVE-2026-42898

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …

Fix: 9.1.45.11+
Fix from $2,300 2026-05-12
Data Formulator HIGH 8.8
CVE-2026-41094

Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.

Fix: 0.7+
Fix from $1,950 2026-05-12
Kiota HIGH 7.8
CVE-2026-41134

Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnera…

Fix: 1.31.1+
Fix from $1,950 2026-04-22
Semantic Kernel CRITICAL 9.9
CVE-2026-26030

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within t…

Fix: 1.39.4+
Fix from $2,300 2026-02-19
Defender For Endpoint HIGH 8.8
CVE-2026-21537

Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adj…

Mitigation only
Fix from $1,950 2026-02-10
Visual Studio 2022 HIGH 8.8
CVE-2026-21256

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attack…

Fix: 17.14.26+
Fix from $1,950 2026-02-10
Azure Container Apps CRITICAL 10.0
CVE-2025-65037

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2025-12-18
Purview HIGH 7.2
CVE-2025-64676

'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2025-12-18
Edge Chromium HIGH 7.6
CVE-2025-59251

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 140.0.3485.81+
Fix from $1,950 2025-09-24
Sharepoint Server HIGH 8.8
CVE-2025-49704 KEVEPSS 100%

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-07-08
Azure Monitor Agent HIGH 7.5
CVE-2025-47988

Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent net…

Fix: 1.35.1+
Fix from $1,950 2025-07-08
Edge Chromium MEDIUM 6.5
CVE-2025-29806

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 129.0.2792.52+
Fix from $1,600 2025-03-23
Dataverse HIGH 8.8
CVE-2025-29807

Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2025-03-21
Windows 10 1809 HIGH 8.8
CVE-2025-21292

Windows Search Service Elevation of Privilege Vulnerability

Fix: 10.0.17763.6775 / 10.0.19044.5371+
Fix from $1,950 2025-01-14
Power Automate For Desktop HIGH 7.8
CVE-2025-21187

Microsoft Power Automate Remote Code Execution Vulnerability

Fix: 2.46.184.25013 / 2.47.126.25010+
Fix from $1,950 2025-01-14
Torchgeo HIGH 8.1
CVE-2024-49048

TorchGeo Remote Code Execution Vulnerability

Fix: 0.6.1+
Fix from $1,950 2024-11-12
Azure Cyclecloud HIGH 8.8
CVE-2024-43469

Azure CycleCloud Remote Code Execution Vulnerability

Fix: 8.6.4+
Fix from $1,950 2024-09-10
Edge Chromium MEDIUM 5.0
CVE-2024-29991

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Fix: 124.0.2478.51+
Fix from $1,600 2024-04-19
365 Apps HIGH 8.8
CVE-2024-21378EPSS 11%

Microsoft Outlook Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2024-02-13
Windows 10 1507 HIGH 7.6
CVE-2024-21351 KEVEPSS 30%

Windows SmartScreen Security Feature Bypass Vulnerability

Fix: 10.0.10240.20469 / 10.0.14393.6709+
Fix from $1,950 2024-02-13
Azure Uamqp HIGH 8.1
CVE-2024-25110EPSS 7%

The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-aft…

Fix: 2024-02-01+
Fix from $1,950 2024-02-12