Vulnerability index

Browse CVEs

3,135 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-47290 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-50652 Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. .net Framework Mitigation only Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-50653 Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. .net Framework No fix yet Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-48581 Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. Surface Go 2 1901 Firmware No fix yet Fix from $1,9502026-07-14 CRITICAL 9.6 CVE-2026-48561 Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker … 365 Copilot Mitigation only Fix from $2,3002026-07-14 HIGH 8.8 CVE-2026-47632 Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network. Azure Connected Machine Agent Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.1 CVE-2026-47646 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker t… Dynamics 365 Customer Voice Mitigation only Fix from $1,6002026-07-09 HIGH 8.8 CVE-2026-45499 Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. Azure Openai Mitigation only Fix from $1,9502026-07-02 HIGH 8.8 CVE-2026-54998 Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. Exchange Online No fix yet Fix from $1,9502026-07-02 HIGH 8.8 CVE-2026-57100 Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a ne… Entra Provisioning Service Mitigation only Fix from $1,9502026-07-02 CRITICAL 9.3 CVE-2026-41106 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 365 Copilot Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-26145 Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. Azure Synapse No fix yet Fix from $2,3002026-07-02 HIGH 7.5 CVE-2025-66389 GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpa… Github Copilot No fix yet Fix from $1,9502026-06-22 HIGH 8.8 CVE-2026-48584 Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. Azure Synapse No fix yet Fix from $1,9502026-06-19 CRITICAL 9.6 CVE-2026-48582 Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. Exchange Online Mitigation only Fix from $2,3002026-06-19 HIGH 8.8 CVE-2026-47645 Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges ov… 365 Copilot Mitigation only Fix from $1,9502026-06-19 CRITICAL 10.0 CVE-2026-45480 Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. Azure Active Directory No fix yet Fix from $2,3002026-06-19 HIGH 7.5 CVE-2026-42895 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t… 365 Copilot Mitigation only Fix from $1,9502026-06-19 MEDIUM 5.4 CVE-2026-32208 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform s… Edge Chromium Mitigation only Fix from $1,6002026-06-19 CRITICAL 9.1 CVE-2025-62821 Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the report… Heif Image Extension No fix yet Fix from $2,3002026-06-19 HIGH 7.5 CVE-2026-54130 Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. 365 Copilot Mitigation only Fix from $1,9502026-06-18 CRITICAL 9.9 CVE-2026-47647 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. Dynamics 365 Mitigation only Fix from $2,3002026-06-18 HIGH 7.5 CVE-2026-47633 Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose inf… Cost Management No fix yet Fix from $1,9502026-06-18 HIGH 8.8 CVE-2026-32174 Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. Azure Ai Bot Service Mitigation only Fix from $1,9502026-06-18 HIGH 7.0 CVE-2026-50656EPSS 11% Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RogueP… Malware Protection Engine No fix yet Fix from $1,9502026-06-16 HIGH 7.8 CVE-2026-48565 Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. Windows Narrator Braille Mitigation only Fix from $1,9502026-06-09 HIGH 8.4 CVE-2026-47635 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Office 2024 Mitigation only Fix from $1,9502026-06-09 HIGH 7.0 CVE-2026-47293 Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. 365 Apps Mitigation only Fix from $1,9502026-06-09 HIGH 7.1 CVE-2026-45649 Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. Excel No fix yet Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-45645 Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-06-09