Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pc Manager HIGH 7.8
CVE-2026-50512

Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.21.6.0+
Fix from $1,950 2026-06-09
Pc Manager HIGH 7.8
CVE-2026-50511

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.21.6.0+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.5
CVE-2026-50508EPSS 9%

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.14393.9234 / 10.0.19045.7417+
Fix from $1,950 2026-06-09
Windows 10 1607 MEDIUM 6.8
CVE-2026-50507EPSS 5%

Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Pc Manager HIGH 7.8
CVE-2026-49161

Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.

Fix: 3.21.6.0+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.9
CVE-2026-48576

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.9
CVE-2026-48578

Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.9
CVE-2026-48575

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-48574

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-48583

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.5
CVE-2026-49160EPSS 54%

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.9
CVE-2026-48573

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.9
CVE-2026-48568

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.9
CVE-2026-48570

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows Narrator Braille HIGH 7.8
CVE-2026-48565

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-06-09
Windows 11 24h2 MEDIUM 5.5
CVE-2026-48566

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8390 / 10.0.26100.32772+
Fix from $1,600 2026-06-09
Visual Studio Code MEDIUM 5.5
CVE-2026-48569

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Fix: 1.123.2+
Fix from $1,600 2026-06-09
Windows 10 1809 HIGH 7.5
CVE-2026-48563

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,950 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-48560

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Windows 10 1607 HIGH 7.9
CVE-2026-47656

Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Azure Stack Edge CRITICAL 9.8
CVE-2026-47643

External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.

Fix: 3.3.2604.3097+
Fix from $2,300 2026-06-09
Windows 10 1607 HIGH 8.8
CVE-2026-47653

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 11 23h2 HIGH 8.2
CVE-2026-47652

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

Fix: 10.0.20348.5256 / 10.0.22631.7219+
Fix from $1,950 2026-06-09
Windows Server 2016 HIGH 7.5
CVE-2026-47654

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-47648

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47641

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47640

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Office 2024 HIGH 8.4
CVE-2026-47635

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-06-09
Sharepoint Server HIGH 8.0
CVE-2026-47298

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20384+
Fix from $1,950 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47634

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorize…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09