Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

365 Apps MEDIUM 5.5
CVE-2026-48580

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Fix: 16.0.10417.20175+
Fix from $1,600 2026-07-14
365 Apps HIGH 7.8
CVE-2026-47642

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
Sql Server 2016 HIGH 8.8
CVE-2026-47295

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6500.1 / 13.0.7095.1+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-47290

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Patch available
Fix from $1,950 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-58644 KEVEPSS 45%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-58640

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Power Bi Report Server MEDIUM 5.4
CVE-2026-58647

Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing ov…

Fix: 15.0.1121.120+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-58609

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-58610

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
365 Apps HIGH 7.8
CVE-2026-58618

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20175+
Fix from $1,950 2026-07-14
Windows Admin Center HIGH 7.8
CVE-2026-58631

Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

Fix: 2606+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-58635

Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elev…

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Pc Manager HIGH 7.8
CVE-2026-58636

Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.21.6.0+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-58614

Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Bing Search HIGH 8.1
CVE-2026-58595

Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.

Fix: 33.4.440529002+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-58526

Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-58601

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 7.8
CVE-2026-58602

Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.5
CVE-2026-58608

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized …

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Azure Cyclecloud MEDIUM 6.5
CVE-2026-58279

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

Fix: 8.9.1+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 7.5
CVE-2026-57979

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 6.5
CVE-2026-57976

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows Admin Center HIGH 8.8
CVE-2026-56169

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 2606+
Fix from $1,950 2026-07-14
Azure Cyclecloud HIGH 8.8
CVE-2026-57969

Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

Fix: 8.9.1+
Fix from $1,950 2026-07-14
Windows Admin Center HIGH 7.8
CVE-2026-57107

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

Fix: 2606+
Fix from $1,950 2026-07-14
.net HIGH 7.5
CVE-2026-56170

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Fix: 8.0.29 / 9.0.18+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 6.8
CVE-2026-57097

Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows Admin Center MEDIUM 6.5
CVE-2026-56185

Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

Fix: 2511+
Fix from $1,600 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-56164 KEVEPSS 22%

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Malware Protection Engine HIGH 7.8
CVE-2026-55012

Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.

Fix: 1.1.26060.3008+
Fix from $1,950 2026-07-14