Vulnerability index

Browse CVEs

3,038 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Windows 11 21h2 MEDIUM 6.5
CVE-2022-40733

An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 ve…

No fix yet
Fix from $1,600 2024-12-18
Update Catalog CRITICAL 9.8
CVE-2024-49147

Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.

Mitigation only
Fix from $2,300 2024-12-12
Defender For Endpoint MEDIUM 6.5
CVE-2024-49071

Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker t…

Mitigation only
Fix from $1,600 2024-12-12
365 Apps HIGH 7.8
CVE-2024-49142

Microsoft Access Remote Code Execution Vulnerability

No fix yet
Fix from $1,950 2024-12-12
Sharepoint Server HIGH 7.4
CVE-2024-49070

Microsoft SharePoint Remote Code Execution Vulnerability

Mitigation only
Fix from $1,950 2024-12-12
Sharepoint Server HIGH 8.2
CVE-2024-49068

Microsoft SharePoint Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2024-12-12
365 Apps HIGH 7.8
CVE-2024-49069

Microsoft Excel Remote Code Execution Vulnerability

Mitigation only
Fix from $1,950 2024-12-12
365 Apps HIGH 7.0
CVE-2024-49059

Microsoft Office Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2024-12-12
Sharepoint Server MEDIUM 6.5
CVE-2024-49062

Microsoft SharePoint Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2024-12-12
Sharepoint Server MEDIUM 6.5
CVE-2024-49064

Microsoft SharePoint Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2024-12-12
365 Apps MEDIUM 5.5
CVE-2024-49065

Microsoft Office Remote Code Execution Vulnerability

No fix yet
Fix from $1,600 2024-12-12
Office HIGH 7.8
CVE-2024-43600

Microsoft Office Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2024-12-12
Azure Functions CRITICAL 9.8
CVE-2024-49052

Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2024-11-26
Partner Center CRITICAL 9.8
CVE-2024-49035 KEV

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2024-11-26
Copilot Studio CRITICAL 9.6
CVE-2024-49038

Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation…

Mitigation only
Fix from $2,300 2024-11-26
Airlift Microsoft Com HIGH 8.8
CVE-2024-49056

Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2024-11-12
Copilot Studio HIGH 7.5
CVE-2024-43610

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through …

Mitigation only
Fix from $1,950 2024-10-09
Configuration Manager 2403 CRITICAL 9.8
CVE-2024-43468 KEVEPSS 61%

Microsoft Configuration Manager Remote Code Execution Vulnerability

No fix yet
Fix from $2,300 2024-10-08
High Definition Audio Bus Driver MEDIUM 5.0
CVE-2024-45383

A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBu…

No fix yet
Fix from $1,600 2024-09-12
Entra Id HIGH 7.5
CVE-2024-43477

Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable …

Mitigation only
Fix from $1,950 2024-08-23
Azure Managed Instance For Apache Cassandra HIGH 8.8
CVE-2024-38175

An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges ov…

Mitigation only
Fix from $1,950 2024-08-20
Dynamics 365 CRITICAL 9.8
CVE-2024-38182

Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2024-07-31
Power Platform CRITICAL 9.8
CVE-2024-35260

An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.

No fix yet
Fix from $2,300 2024-06-27
Telemetry Dashboard MEDIUM 5.5
CVE-2024-30472

Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local acces…

Mitigation only
Fix from $1,600 2024-06-13
Azure Cyclecloud HIGH 8.8
CVE-2024-29993

Azure CycleCloud Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2024-04-09
Azure Ai Search MEDIUM 5.5
CVE-2024-29063

Azure AI Search Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2024-04-09
365 Apps HIGH 7.8
CVE-2024-26257

Microsoft Excel Remote Code Execution Vulnerability

No fix yet
Fix from $1,950 2024-04-09
Azure Compute Gallery MEDIUM 6.5
CVE-2024-21424

Azure Compute Gallery Elevation of Privilege Vulnerability

No fix yet
Fix from $1,600 2024-04-09
.net Framework HIGH 7.5
CVE-2024-29059 KEVEPSS 99%

.NET Framework Information Disclosure Vulnerability

Mitigation only
Fix from $1,950 2024-03-23
Exchange Server HIGH 8.8
CVE-2024-26198EPSS 7%

Microsoft Exchange Server Remote Code Execution Vulnerability

No fix yet
Fix from $1,950 2024-03-12