Vulnerability index

Browse CVEs

3,135 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Azure Iot Central CRITICAL 9.9
CVE-2026-21515

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-24
Entra Id CRITICAL 10.0
CVE-2026-35431

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

Mitigation only
Fix from $2,300 2026-04-23
Bing CRITICAL 9.8
CVE-2026-33819

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-04-23
365 Copilot CRITICAL 9.3
CVE-2026-33102

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-23
Dynamics 365 HIGH 7.5
CVE-2026-32210

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

Mitigation only
Fix from $1,950 2026-04-23
Power Apps HIGH 8.0
CVE-2026-32172

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2026-04-23
Purview Ediscovery CRITICAL 10.0
CVE-2026-26150

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-23
Partner Center CRITICAL 9.6
CVE-2026-24303

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-23
365 Apps MEDIUM 6.1
CVE-2026-33822

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Mitigation only
Fix from $1,600 2026-04-14
365 Apps HIGH 8.4
CVE-2026-33114

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
365 Apps HIGH 8.4
CVE-2026-33115

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
365 Apps HIGH 7.8
CVE-2026-33095

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-04-14
.net Framework MEDIUM 5.9
CVE-2026-32226

Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny…

No fix yet
Fix from $1,600 2026-04-14
365 Apps HIGH 7.8
CVE-2026-32200

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
365 Apps HIGH 8.4
CVE-2026-32190

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
365 Apps HIGH 7.8
CVE-2026-32189

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
365 Apps HIGH 7.1
CVE-2026-32188

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Mitigation only
Fix from $1,950 2026-04-14
Azure Logic Apps HIGH 8.8
CVE-2026-32171

Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-04-14
365 Apps HIGH 7.8
CVE-2026-23657

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
.net Framework HIGH 7.5
CVE-2026-23666

Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.

Mitigation only
Fix from $1,950 2026-04-14
Bing CRITICAL 9.8
CVE-2026-32186

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-03
Azure Kubernetes Service CRITICAL 9.8
CVE-2026-33105

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Databricks CRITICAL 9.8
CVE-2026-33107

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Ai Foundry CRITICAL 9.8
CVE-2026-32213

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Custom Locations Resource Provider HIGH 8.8
CVE-2026-26135

Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a networ…

Mitigation only
Fix from $1,950 2026-04-03
Azure Sre Agent HIGH 7.5
CVE-2026-32173

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-04-03
Azure Web Apps HIGH 7.5
CVE-2026-32211

Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-04-03
Bing Images CRITICAL 9.8
CVE-2026-32194

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execu…

No fix yet
Fix from $2,300 2026-03-19
Azure Cloud Shell CRITICAL 9.8
CVE-2026-32169

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-03-19
Bing Images CRITICAL 9.8
CVE-2026-32191

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t…

Mitigation only
Fix from $2,300 2026-03-19