Vulnerability index

Browse CVEs

3,135 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-23652 Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execu… Power Pages Mitigation only Fix from $2,3002026-05-22 HIGH 7.7 CVE-2026-26147 Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. Azure Stack Hci Mitigation only Fix from $1,9502026-05-22 HIGH 7.5 CVE-2026-23663 Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. Global Secure Access No fix yet Fix from $1,9502026-05-22 MEDIUM 6.8 CVE-2026-45585 Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this… Windows 11 24h2 No fix yet Fix from $1,6002026-05-20 CRITICAL 9.9 CVE-2026-42823 Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. Azure Logic Apps Mitigation only Fix from $2,3002026-05-12 HIGH 8.8 CVE-2026-40420 Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. 365 Apps Mitigation only Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-40419 Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. 365 Apps Mitigation only Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-40417 Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. Dynamics 365 Business Central Mitigation only Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-40418 Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. 365 Apps Mitigation only Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-40379 Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. Entra Id No fix yet Fix from $1,9502026-05-12 HIGH 8.4 CVE-2026-40364 Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-05-12 HIGH 8.4 CVE-2026-40366 Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-05-12 HIGH 8.4 CVE-2026-40358 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502026-05-12 HIGH 8.4 CVE-2026-40361 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502026-05-12 MEDIUM 5.5 CVE-2026-35440 Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 365 Apps No fix yet Fix from $1,6002026-05-12 HIGH 8.8 CVE-2026-35436 Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. 365 Apps Mitigation only Fix from $1,9502026-05-12 HIGH 8.2 CVE-2026-33833 Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized a… Azure Machine Learning Mitigation only Fix from $1,9502026-05-12 CRITICAL 9.9 CVE-2026-33821 Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. Dynamics 365 Customer Insights Mitigation only Fix from $2,3002026-05-12 HIGH 8.1 CVE-2026-41105 Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. Azure Monitor Action Group Notification System Mitigation only Fix from $1,9502026-05-07 HIGH 7.5 CVE-2026-42826 Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. Azure Devops No fix yet Fix from $1,9502026-05-07 CRITICAL 10.0 CVE-2026-35435 Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. Azure Ai Foundry Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.9 CVE-2026-33109 Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. Azure Managed Instance For Apache Cassandra Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.6 CVE-2026-35428 Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s… Azure Cloud Shell Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.0 CVE-2026-33844 Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. Azure Managed Instance For Apache Cassandra Mitigation only Fix from $2,3002026-05-07 HIGH 8.2 CVE-2026-34327 Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over … Partner Center Mitigation only Fix from $1,9502026-05-07 HIGH 7.5 CVE-2026-33111 Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker … Copilot Chat Mitigation only Fix from $1,9502026-05-07 MEDIUM 6.5 CVE-2026-33823 Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. Teams No fix yet Fix from $1,6002026-05-07 HIGH 7.5 CVE-2026-26129 Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor… 365 Copilot Chat No fix yet Fix from $1,9502026-05-07 HIGH 7.5 CVE-2026-26164 Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor… 365 Copilot Chat No fix yet Fix from $1,9502026-05-07 MEDIUM 6.1 CVE-2026-32207 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to per… Azure Machine Learning Mitigation only Fix from $1,6002026-05-07