Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 11 23h2 HIGH 7.0
CVE-2026-48571

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22631.7376 / 10.0.26100.8875+
Fix from $1,950 2026-07-14
Windows 11 23h2 HIGH 7.0
CVE-2026-48572

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to…

Fix: 10.0.22631.7376 / 10.0.26100.8875+
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 7.0
CVE-2026-49162

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,950 2026-07-14
365 Copilot CRITICAL 9.6
CVE-2026-48561

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …

Mitigation only
Fix from $2,300 2026-07-14
Azure Connected Machine Agent HIGH 8.8
CVE-2026-47632

Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

Mitigation only
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.8
CVE-2026-48564

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Asp.net Core Odata HIGH 7.5
CVE-2026-45646

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Fix: 7.8.0 / 9.5.0+
Fix from $1,950 2026-07-14
Sql Server 2016 HIGH 7.5
CVE-2026-47296

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6500.1 / 13.0.7095.1+
Fix from $1,950 2026-07-14
Visual Studio Code MEDIUM 6.5
CVE-2026-47282

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Fix: 1.128.1+
Fix from $1,600 2026-07-14
Visual Studio Code MEDIUM 5.5
CVE-2026-45496

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a secu…

Fix: 1.128.1+
Fix from $1,600 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-42990

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 HIGH 8.8
CVE-2026-42975

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-42982

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 11 23h2 HIGH 7.8
CVE-2026-44800

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack…

Fix: 10.0.22631.7376 / 10.0.26100.8875+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.5
CVE-2026-44806

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.1
CVE-2026-42900

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to e…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.0
CVE-2026-40400

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.5
CVE-2026-40378

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny ser…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-40422

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-41087

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1809 MEDIUM 6.5
CVE-2026-34348

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-33842

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1809 MEDIUM 5.5
CVE-2026-34328

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,600 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-34346

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose informatio…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1809 MEDIUM 5.5
CVE-2026-34349

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,600 2026-07-14
Edge Chromium HIGH 8.3
CVE-2026-58596

Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-12
Edge Chromium HIGH 8.3
CVE-2026-58281

Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-11
Dynamics 365 Customer Voice MEDIUM 6.1
CVE-2026-47646

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker t…

Mitigation only
Fix from $1,600 2026-07-09
Edge Chromium HIGH 8.2
CVE-2026-58525

Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Fix: 150.0.4078.50+
Fix from $1,950 2026-07-08
Edge Chromium MEDIUM 6.5
CVE-2026-58523

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03