Vulnerability index

Browse CVEs

3,038 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-40733 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 ve… Windows 11 21h2 No fix yet Fix from $1,6002024-12-18 CRITICAL 9.8 CVE-2024-49147 Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver. Update Catalog Mitigation only Fix from $2,3002024-12-12 MEDIUM 6.5 CVE-2024-49071 Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker t… Defender For Endpoint Mitigation only Fix from $1,6002024-12-12 HIGH 7.8 CVE-2024-49142 Microsoft Access Remote Code Execution Vulnerability 365 Apps No fix yet Fix from $1,9502024-12-12 HIGH 7.4 CVE-2024-49070 Microsoft SharePoint Remote Code Execution Vulnerability Sharepoint Server Mitigation only Fix from $1,9502024-12-12 HIGH 8.2 CVE-2024-49068 Microsoft SharePoint Elevation of Privilege Vulnerability Sharepoint Server Mitigation only Fix from $1,9502024-12-12 HIGH 7.8 CVE-2024-49069 Microsoft Excel Remote Code Execution Vulnerability 365 Apps Mitigation only Fix from $1,9502024-12-12 HIGH 7.0 CVE-2024-49059 Microsoft Office Elevation of Privilege Vulnerability 365 Apps No fix yet Fix from $1,9502024-12-12 MEDIUM 6.5 CVE-2024-49062 Microsoft SharePoint Information Disclosure Vulnerability Sharepoint Server No fix yet Fix from $1,6002024-12-12 MEDIUM 6.5 CVE-2024-49064 Microsoft SharePoint Information Disclosure Vulnerability Sharepoint Server No fix yet Fix from $1,6002024-12-12 MEDIUM 5.5 CVE-2024-49065 Microsoft Office Remote Code Execution Vulnerability 365 Apps No fix yet Fix from $1,6002024-12-12 HIGH 7.8 CVE-2024-43600 Microsoft Office Elevation of Privilege Vulnerability Office No fix yet Fix from $1,9502024-12-12 CRITICAL 9.8 CVE-2024-49052 Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. Azure Functions Mitigation only Fix from $2,3002024-11-26 CRITICAL 9.8 CVE-2024-49035 KEV An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. Partner Center Mitigation only Fix from $2,3002024-11-26 CRITICAL 9.6 CVE-2024-49038 Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation… Copilot Studio Mitigation only Fix from $2,3002024-11-26 HIGH 8.8 CVE-2024-49056 Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network. Airlift Microsoft Com Mitigation only Fix from $1,9502024-11-12 HIGH 7.5 CVE-2024-43610 Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through … Copilot Studio Mitigation only Fix from $1,9502024-10-09 CRITICAL 9.8 CVE-2024-43468 KEVEPSS 61% Microsoft Configuration Manager Remote Code Execution Vulnerability Configuration Manager 2403 No fix yet Fix from $2,3002024-10-08 MEDIUM 5.0 CVE-2024-45383 A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBu… High Definition Audio Bus Driver No fix yet Fix from $1,6002024-09-12 HIGH 7.5 CVE-2024-43477 Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable … Entra Id Mitigation only Fix from $1,9502024-08-23 HIGH 8.8 CVE-2024-38175 An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges ov… Azure Managed Instance For Apache Cassandra Mitigation only Fix from $1,9502024-08-20 CRITICAL 9.8 CVE-2024-38182 Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. Dynamics 365 Mitigation only Fix from $2,3002024-07-31 CRITICAL 9.8 CVE-2024-35260 An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network. Power Platform No fix yet Fix from $2,3002024-06-27 MEDIUM 5.5 CVE-2024-30472 Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local acces… Telemetry Dashboard Mitigation only Fix from $1,6002024-06-13 HIGH 8.8 CVE-2024-29993 Azure CycleCloud Elevation of Privilege Vulnerability Azure Cyclecloud No fix yet Fix from $1,9502024-04-09 MEDIUM 5.5 CVE-2024-29063 Azure AI Search Information Disclosure Vulnerability Azure Ai Search No fix yet Fix from $1,6002024-04-09 HIGH 7.8 CVE-2024-26257 Microsoft Excel Remote Code Execution Vulnerability 365 Apps No fix yet Fix from $1,9502024-04-09 MEDIUM 6.5 CVE-2024-21424 Azure Compute Gallery Elevation of Privilege Vulnerability Azure Compute Gallery No fix yet Fix from $1,6002024-04-09 HIGH 7.5 CVE-2024-29059 KEVEPSS 99% .NET Framework Information Disclosure Vulnerability .net Framework Mitigation only Fix from $1,9502024-03-23 HIGH 8.8 CVE-2024-26198EPSS 7% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server No fix yet Fix from $1,9502024-03-12