Vulnerability index

Browse CVEs

3,135 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Azure Data Explorer HIGH 7.4
CVE-2026-21524

Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a netw…

No fix yet
Fix from $1,950 2026-01-22
Account MEDIUM 6.1
CVE-2026-21264

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform …

Mitigation only
Fix from $1,600 2026-01-22
365 Apps HIGH 8.4
CVE-2026-20953

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20956

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-01-13
365 Apps HIGH 8.4
CVE-2026-20952

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20946

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20948

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20949

Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

No fix yet
Fix from $1,950 2026-01-13
365 Apps HIGH 8.4
CVE-2026-20944

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-01-13
Azure Cosmos Db CRITICAL 9.6
CVE-2025-64675

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform sp…

Mitigation only
Fix from $2,300 2025-12-19
Azure Container Apps CRITICAL 10.0
CVE-2025-65037

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2025-12-18
Partner Center CRITICAL 9.8
CVE-2025-65041

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-12-18
Office Out Of Box Experience HIGH 8.2
CVE-2025-64677

Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker …

Mitigation only
Fix from $1,950 2025-12-18
Azure Language HIGH 8.8
CVE-2025-64663

Custom Question Answering Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2025-12-18
Purview HIGH 7.2
CVE-2025-64676

'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2025-12-18
365 Apps HIGH 7.8
CVE-2025-62562

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62557

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62558

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62559

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62552

Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62553

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.8
CVE-2025-62554

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2025-12-09
365 Apps HIGH 7.0
CVE-2025-62555

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2025-12-09
Azure Application Gateway CRITICAL 9.8
CVE-2025-64656

Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-11-26
Azure Application Gateway CRITICAL 9.8
CVE-2025-64657

Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-11-26
Dynamics Omnichannel Sdk Storage Containers CRITICAL 9.8
CVE-2025-64655

Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-11-20
365 Defender Portal MEDIUM 6.1
CVE-2025-62459

Microsoft Defender Portal Spoofing Vulnerability

No fix yet
Fix from $1,600 2025-11-20
Azure Monitor CRITICAL 9.8
CVE-2025-62207

Azure Monitor Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-11-20
Sharepoint Online CRITICAL 9.8
CVE-2025-59245

Microsoft SharePoint Online Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-11-20
Azure Bastion Developer CRITICAL 10.0
CVE-2025-49752

Azure Bastion Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-11-20