Vulnerability index

Browse CVEs

3,135 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Power Pages CRITICAL 9.8
CVE-2026-23652

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execu…

Mitigation only
Fix from $2,300 2026-05-22
Azure Stack Hci HIGH 7.7
CVE-2026-26147

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-05-22
Global Secure Access HIGH 7.5
CVE-2026-23663

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-05-22
Windows 11 24h2 MEDIUM 6.8
CVE-2026-45585

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this…

No fix yet
Fix from $1,600 2026-05-20
Azure Logic Apps CRITICAL 9.9
CVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-12
365 Apps HIGH 8.8
CVE-2026-40420

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-05-12
365 Apps HIGH 7.8
CVE-2026-40419

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-05-12
Dynamics 365 Business Central HIGH 7.8
CVE-2026-40417

Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-05-12
365 Apps HIGH 7.8
CVE-2026-40418

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-05-12
Entra Id HIGH 7.5
CVE-2026-40379

Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

No fix yet
Fix from $1,950 2026-05-12
365 Apps HIGH 8.4
CVE-2026-40364

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-05-12
365 Apps HIGH 8.4
CVE-2026-40366

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-05-12
365 Apps HIGH 8.4
CVE-2026-40358

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-05-12
365 Apps HIGH 8.4
CVE-2026-40361

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-05-12
365 Apps MEDIUM 5.5
CVE-2026-35440

Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $1,600 2026-05-12
365 Apps HIGH 8.8
CVE-2026-35436

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-05-12
Azure Machine Learning HIGH 8.2
CVE-2026-33833

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized a…

Mitigation only
Fix from $1,950 2026-05-12
Dynamics 365 Customer Insights CRITICAL 9.9
CVE-2026-33821

Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-12
Azure Monitor Action Group Notification System HIGH 8.1
CVE-2026-41105

Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-05-07
Azure Devops HIGH 7.5
CVE-2026-42826

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $1,950 2026-05-07
Azure Ai Foundry CRITICAL 10.0
CVE-2026-35435

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-07
Azure Managed Instance For Apache Cassandra CRITICAL 9.9
CVE-2026-33109

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-05-07
Azure Cloud Shell CRITICAL 9.6
CVE-2026-35428

Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s…

Mitigation only
Fix from $2,300 2026-05-07
Azure Managed Instance For Apache Cassandra CRITICAL 9.0
CVE-2026-33844

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-05-07
Partner Center HIGH 8.2
CVE-2026-34327

Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over …

Mitigation only
Fix from $1,950 2026-05-07
Copilot Chat HIGH 7.5
CVE-2026-33111

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …

Mitigation only
Fix from $1,950 2026-05-07
Teams MEDIUM 6.5
CVE-2026-33823

Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $1,600 2026-05-07
365 Copilot Chat HIGH 7.5
CVE-2026-26129

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…

No fix yet
Fix from $1,950 2026-05-07
365 Copilot Chat HIGH 7.5
CVE-2026-26164

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…

No fix yet
Fix from $1,950 2026-05-07
Azure Machine Learning MEDIUM 6.1
CVE-2026-32207

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to per…

Mitigation only
Fix from $1,600 2026-05-07