Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Power Pages CRITICAL 9.8
CVE-2026-23652

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execu…

Mitigation only
Fix from $2,300 2026-05-22
Azure Stack Hci HIGH 7.7
CVE-2026-26147

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-05-22
Global Secure Access HIGH 7.5
CVE-2026-23663

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-05-22
Malware Protection Engine HIGH 8.1
CVE-2026-45584

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

Fix: 1.1.26040.8+
Fix from $1,950 2026-05-20
Defender Antimalware Platform HIGH 7.5
CVE-2026-45498 KEVEPSS 63%

Microsoft Defender Denial of Service Vulnerability

Fix: 4.18.26040.7+
Fix from $1,950 2026-05-20
Windows Admin Center HIGH 7.8
CVE-2026-42834

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 0.72.0.0+
Fix from $1,950 2026-05-20
Malware Protection Engine HIGH 7.8
CVE-2026-41091 KEVEPSS 10%

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Fix: 1.1.26040.8+
Fix from $1,950 2026-05-20
Windows 11 24h2 MEDIUM 6.8
CVE-2026-45585

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this…

No fix yet
Fix from $1,600 2026-05-20
Edge Chromium CRITICAL 9.8
CVE-2026-45495

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 148.0.3967.70+
Fix from $2,300 2026-05-18
Edge Chromium MEDIUM 6.1
CVE-2026-45494

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Fix: 148.0.3967.70+
Fix from $1,600 2026-05-18
Edge Chromium MEDIUM 5.4
CVE-2026-45492

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Fix: 148.0.3967.70+
Fix from $1,600 2026-05-18
Azure Local CRITICAL 10.0
CVE-2026-42822

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

Fix: 2604.2.25645+
Fix from $2,300 2026-05-18
Exchange Server MEDIUM 6.1
CVE-2026-42897 KEVEPSS 70%

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …

Fix: 15.02.2562.043+
Fix from $1,600 2026-05-14
Authenticator HIGH 7.4
CVE-2026-41615

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a …

Fix: 6.8.47 / 6.2605.2973+
Fix from $1,950 2026-05-14
Dynamics 365 CRITICAL 9.9
CVE-2026-42898

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …

Fix: 9.1.45.11+
Fix from $2,300 2026-05-12
Windows 11 24h2 HIGH 7.8
CVE-2026-42896

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8457 / 10.0.26100.32860+
Fix from $1,950 2026-05-12
Outlook HIGH 7.5
CVE-2026-42893

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tamper…

Fix: 5.2617.1+
Fix from $1,950 2026-05-12
.net HIGH 7.5
CVE-2026-42899

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Fix: 8.0.27 / 9.0.16+
Fix from $1,950 2026-05-12
Edge Chromium MEDIUM 6.5
CVE-2026-42891

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing …

Fix: 148.0.3967.55+
Fix from $1,600 2026-05-12
Edge Chromium MEDIUM 5.4
CVE-2026-42838

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unaut…

Fix: 148.0.3967.55+
Fix from $1,600 2026-05-12
Azure Logic Apps CRITICAL 9.9
CVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-12
Dynamics 365 CRITICAL 9.1
CVE-2026-42833

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …

Fix: 9.1.45.11+
Fix from $2,300 2026-05-12
365 Copilot HIGH 7.8
CVE-2026-42831

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.19822.20190+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-42825

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Azure Monitor Agent MEDIUM 6.5
CVE-2026-42830

Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.42.0+
Fix from $1,600 2026-05-12
Excel MEDIUM 5.5
CVE-2026-42832

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

Fix: 16.0.19822.20190+
Fix from $1,600 2026-05-12
Visual Studio Code HIGH 8.8
CVE-2026-41613

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Fix: 1.119.1+
Fix from $1,950 2026-05-12
365 Copilot MEDIUM 6.2
CVE-2026-41614

Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.

Fix: 19.2604.43111.0+
Fix from $1,600 2026-05-12
Live Preview MEDIUM 5.5
CVE-2026-41612

Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.

Fix: 0.4.19+
Fix from $1,600 2026-05-12
Visual Studio Code HIGH 8.8
CVE-2026-41109

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unau…

Fix: 1.119.1+
Fix from $1,950 2026-05-12