Vulnerability index

Browse CVEs

3,135 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Purview CRITICAL 10.0
CVE-2026-26138

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-03-19
365 Copilot Chat CRITICAL 9.9
CVE-2026-26137

Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-03-19
Purview HIGH 8.6
CVE-2026-26139

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-03-19
Copilot HIGH 7.5
CVE-2026-26136

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose …

Mitigation only
Fix from $1,950 2026-03-19
Bing HIGH 7.5
CVE-2026-26120

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.

No fix yet
Fix from $1,950 2026-03-19
365 Copilot MEDIUM 5.3
CVE-2026-24299

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…

Mitigation only
Fix from $1,600 2026-03-19
Azure Data Factory HIGH 7.5
CVE-2026-23659

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a netwo…

No fix yet
Fix from $1,950 2026-03-19
Azure Devops CRITICAL 9.8
CVE-2026-23658

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-03-19
Sharepoint Server HIGH 8.8
CVE-2026-26114

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2026-03-10
System Center Operations Manager HIGH 8.8
CVE-2026-20967

Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-03-10
Payment Orchestrator Service CRITICAL 9.8
CVE-2026-26125

Payment Orchestrator Service Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-03-05
Aci Confidential Containers MEDIUM 6.7
CVE-2026-23651

Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,600 2026-03-05
Aci Confidential Containers MEDIUM 6.7
CVE-2026-26124

'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $1,600 2026-03-05
Aci Confidential Containers MEDIUM 6.5
CVE-2026-26122

Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $1,600 2026-03-05
Devices Pricing Program CRITICAL 9.8
CVE-2026-21536

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

No fix yet
Fix from $2,300 2026-03-05
Teams HIGH 7.5
CVE-2026-21535

Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-02-19
Azure Conversation Authoring Client Library CRITICAL 9.8
CVE-2026-21531

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-02-10
Defender For Endpoint HIGH 8.8
CVE-2026-21537

Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adj…

Mitigation only
Fix from $1,950 2026-02-10
365 Apps HIGH 7.8
CVE-2026-21514 KEV

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

Mitigation only
Fix from $1,950 2026-02-10
Azure Front Door CRITICAL 9.8
CVE-2026-24300

Azure Front Door Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-02-05
Azure Arc CRITICAL 9.8
CVE-2026-24302

Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-02-05
Azure Functions HIGH 8.2
CVE-2026-21532

Azure Function Information Disclosure Vulnerability

No fix yet
Fix from $1,950 2026-02-05
365 Apps HIGH 7.8
CVE-2026-21509 KEVEPSS 72%

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Mitigation only
Fix from $1,950 2026-01-26
Azure Resource Manager CRITICAL 9.9
CVE-2026-24304

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-01-23
365 Copilot HIGH 7.5
CVE-2026-24307

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-01-22
Entra Id CRITICAL 9.8
CVE-2026-24305

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-01-22
Azure Front Door CRITICAL 9.8
CVE-2026-24306

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-01-22
Azure Logic Apps CRITICAL 9.8
CVE-2026-21227

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…

Mitigation only
Fix from $2,300 2026-01-22
Copilot Studio HIGH 7.5
CVE-2026-21520

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through …

Mitigation only
Fix from $1,950 2026-01-22
365 Word Copilot HIGH 7.4
CVE-2026-21521

Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-01-22