Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Edge Chromium HIGH 7.5
CVE-2026-57975

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over…

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium HIGH 7.5
CVE-2026-57984

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium HIGH 7.5
CVE-2026-57986

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium HIGH 7.1
CVE-2026-57977

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attack…

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium MEDIUM 6.5
CVE-2026-57987

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Edge Chromium HIGH 8.8
CVE-2026-56645

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium HIGH 8.8
CVE-2026-57974

Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Edge Chromium MEDIUM 6.5
CVE-2026-45489

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Edge Chromium MEDIUM 6.5
CVE-2026-56646

Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ove…

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Edge Chromium MEDIUM 5.9
CVE-2026-45488

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing …

Fix: 150.0.4078.48+
Fix from $1,600 2026-07-03
Azure Openai HIGH 8.8
CVE-2026-45499

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-07-02
Exchange Online HIGH 8.8
CVE-2026-54998

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-07-02
Entra Provisioning Service HIGH 8.8
CVE-2026-57100

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a ne…

Mitigation only
Fix from $1,950 2026-07-02
365 Copilot CRITICAL 9.3
CVE-2026-41106

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-07-02
Azure Synapse CRITICAL 9.8
CVE-2026-26145

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-02
Edge Chromium HIGH 8.3
CVE-2026-50521

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Fix: 149.0.4022.67+
Fix from $1,950 2026-07-01
Github Copilot HIGH 7.5
CVE-2025-66389

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpa…

No fix yet
Fix from $1,950 2026-06-22
Github Copilot Chat HIGH 7.5
CVE-2026-50519

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose informatio…

Mitigation only
Fix from $1,950 2026-06-19
Azure Synapse HIGH 8.8
CVE-2026-48584

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-06-19
Exchange Online CRITICAL 9.6
CVE-2026-48582

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-06-19
365 Copilot HIGH 8.8
CVE-2026-47645

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges ov…

Mitigation only
Fix from $1,950 2026-06-19
Azure Active Directory CRITICAL 10.0
CVE-2026-45480

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-06-19
365 Copilot HIGH 7.5
CVE-2026-42895

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t…

Mitigation only
Fix from $1,950 2026-06-19
Edge Chromium MEDIUM 5.4
CVE-2026-32208

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform s…

Mitigation only
Fix from $1,600 2026-06-19
Heif Image Extension CRITICAL 9.1
CVE-2025-62821

Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the report…

No fix yet
Fix from $2,300 2026-06-19
365 Copilot HIGH 7.5
CVE-2026-54130

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-06-18
Dynamics 365 CRITICAL 9.9
CVE-2026-47647

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-06-18
Cost Management HIGH 7.5
CVE-2026-47633

Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose inf…

No fix yet
Fix from $1,950 2026-06-18
Azure Ai Bot Service HIGH 8.8
CVE-2026-32174

Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-06-18
Malware Protection Engine HIGH 7.0
CVE-2026-50656EPSS 11%

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RogueP…

No fix yet
Fix from $1,950 2026-06-16