Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sharepoint Server MEDIUM 5.4
CVE-2026-47636

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47639

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Exchange Server MEDIUM 5.4
CVE-2026-47631

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …

Fix: 15.02.2562.043+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47637

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Sharepoint Server MEDIUM 5.4
CVE-2026-47638

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20384+
Fix from $1,600 2026-06-09
Windows 10 1607 CRITICAL 9.8
CVE-2026-47291EPSS 23%

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $2,300 2026-06-09
Windows App HIGH 8.8
CVE-2026-47289

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 2.0.1193.0 / 10.0.14393.9234+
Fix from $1,950 2026-06-09
Visual Studio Code HIGH 7.8
CVE-2026-47292

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

Fix: 1.123.1+
Fix from $1,950 2026-06-09
Windows Server 2012 HIGH 7.1
CVE-2026-47288

Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
365 Apps HIGH 7.0
CVE-2026-47293

Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2026-06-09
Visual Studio Code MEDIUM 6.5
CVE-2026-47284

Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a netwo…

Fix: 1.123.1+
Fix from $1,600 2026-06-09
Visual Studio Code MEDIUM 6.5
CVE-2026-47287

Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.

Fix: 1.123.1+
Fix from $1,600 2026-06-09
Windows 11 23h2 CRITICAL 9.8
CVE-2026-45657EPSS 15%

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

Fix: 10.0.20348.5256 / 10.0.22631.7219+
Fix from $2,300 2026-06-09
Visual Studio Code CRITICAL 9.6
CVE-2026-47281

Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Fix: 1.123.1+
Fix from $2,300 2026-06-09
Windows 10 1607 MEDIUM 6.8
CVE-2026-45658

Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows 11 24h2 HIGH 7.9
CVE-2026-45654

Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.26100.8655 / 10.0.26100.32995+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-45656

Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Excel HIGH 7.1
CVE-2026-45649

Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.

No fix yet
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.0
CVE-2026-45653

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 MEDIUM 5.3
CVE-2026-45655

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,600 2026-06-09
Windows Server 2022 HIGH 8.8
CVE-2026-45648

Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

Fix: 10.0.20348.5256 / 10.0.26100.32995+
Fix from $1,950 2026-06-09
Live Share Canvas HIGH 8.0
CVE-2026-45644

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker…

Fix: 1.4.2+
Fix from $1,950 2026-06-09
Windows 10 21h2 HIGH 7.8
CVE-2026-45641

Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.

Fix: 10.0.19044.7417 / 10.0.19045.7417+
Fix from $1,950 2026-06-09
365 Apps HIGH 7.8
CVE-2026-45645

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-06-09
365 Apps HIGH 7.8
CVE-2026-45643

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-06-09
Defender For Endpoint HIGH 7.0
CVE-2026-45647

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

Fix: 101.26042.0011+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 8.1
CVE-2026-45635

Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code o…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-45636

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows 10 1809 HIGH 7.8
CVE-2026-45637

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8880 / 10.0.19044.7417+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-45638

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09