Vulnerability index

Browse CVEs

3,135 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

365 Apps HIGH 7.8
CVE-2026-47290

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-07-14
.net Framework HIGH 7.5
CVE-2026-50652

Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

Mitigation only
Fix from $1,950 2026-07-14
.net Framework HIGH 7.5
CVE-2026-50653

Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

No fix yet
Fix from $1,950 2026-07-14
Surface Go 2 1901 Firmware HIGH 7.8
CVE-2026-48581

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $1,950 2026-07-14
365 Copilot CRITICAL 9.6
CVE-2026-48561

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …

Mitigation only
Fix from $2,300 2026-07-14
Azure Connected Machine Agent HIGH 8.8
CVE-2026-47632

Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

Mitigation only
Fix from $1,950 2026-07-14
Dynamics 365 Customer Voice MEDIUM 6.1
CVE-2026-47646

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker t…

Mitigation only
Fix from $1,600 2026-07-09
Azure Openai HIGH 8.8
CVE-2026-45499

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-07-02
Exchange Online HIGH 8.8
CVE-2026-54998

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-07-02
Entra Provisioning Service HIGH 8.8
CVE-2026-57100

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a ne…

Mitigation only
Fix from $1,950 2026-07-02
365 Copilot CRITICAL 9.3
CVE-2026-41106

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-07-02
Azure Synapse CRITICAL 9.8
CVE-2026-26145

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-02
Github Copilot HIGH 7.5
CVE-2025-66389

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpa…

No fix yet
Fix from $1,950 2026-06-22
Azure Synapse HIGH 8.8
CVE-2026-48584

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-06-19
Exchange Online CRITICAL 9.6
CVE-2026-48582

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-06-19
365 Copilot HIGH 8.8
CVE-2026-47645

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges ov…

Mitigation only
Fix from $1,950 2026-06-19
Azure Active Directory CRITICAL 10.0
CVE-2026-45480

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-06-19
365 Copilot HIGH 7.5
CVE-2026-42895

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t…

Mitigation only
Fix from $1,950 2026-06-19
Edge Chromium MEDIUM 5.4
CVE-2026-32208

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform s…

Mitigation only
Fix from $1,600 2026-06-19
Heif Image Extension CRITICAL 9.1
CVE-2025-62821

Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the report…

No fix yet
Fix from $2,300 2026-06-19
365 Copilot HIGH 7.5
CVE-2026-54130

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-06-18
Dynamics 365 CRITICAL 9.9
CVE-2026-47647

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-06-18
Cost Management HIGH 7.5
CVE-2026-47633

Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose inf…

No fix yet
Fix from $1,950 2026-06-18
Azure Ai Bot Service HIGH 8.8
CVE-2026-32174

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-06-18
Malware Protection Engine HIGH 7.0
CVE-2026-50656EPSS 11%

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RogueP…

No fix yet
Fix from $1,950 2026-06-16
Windows Narrator Braille HIGH 7.8
CVE-2026-48565

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-06-09
Office 2024 HIGH 8.4
CVE-2026-47635

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-06-09
365 Apps HIGH 7.0
CVE-2026-47293

Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-06-09
Excel HIGH 7.1
CVE-2026-45649

Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.

No fix yet
Fix from $1,950 2026-06-09
365 Apps HIGH 7.8
CVE-2026-45645

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-06-09