Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1607 HIGH 7.8
CVE-2026-33837

Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.8
CVE-2026-33838

Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Dynamics 365 Customer Insights CRITICAL 9.9
CVE-2026-33821

Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-12
Azure Sdk For Java CRITICAL 9.1
CVE-2026-33117

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com…

Fix: 4.10.6+
Fix from $2,300 2026-05-12
Sharepoint Server HIGH 8.8
CVE-2026-33110

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20280+
Fix from $1,950 2026-05-12
Sharepoint Server HIGH 8.8
CVE-2026-33112

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20280+
Fix from $1,950 2026-05-12
Azure Monitor Agent HIGH 7.8
CVE-2026-32204

External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.14.0+
Fix from $1,950 2026-05-12
Teams MEDIUM 5.5
CVE-2026-32185

Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.

Fix: 1.0.0.2026092103+
Fix from $1,600 2026-05-12
Visual Studio 2022 HIGH 7.3
CVE-2026-32177

Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

Fix: 8.0.27 / 9.0.16+
Fix from $1,950 2026-05-12
Windows 10 1607 MEDIUM 6.7
CVE-2026-32170

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,600 2026-05-12
Windows 10 1607 HIGH 7.5
CVE-2026-32161

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthor…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 MEDIUM 6.7
CVE-2026-21530

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,600 2026-05-12
Azure Monitor Action Group Notification System HIGH 8.1
CVE-2026-41105

Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-05-07
Azure Devops HIGH 7.5
CVE-2026-42826

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $1,950 2026-05-07
Azure Ai Foundry CRITICAL 10.0
CVE-2026-35435

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-07
Azure Managed Instance For Apache Cassandra CRITICAL 9.9
CVE-2026-33109

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-05-07
Azure Cloud Shell CRITICAL 9.6
CVE-2026-35428

Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s…

Mitigation only
Fix from $2,300 2026-05-07
Azure Managed Instance For Apache Cassandra CRITICAL 9.0
CVE-2026-33844

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-05-07
Partner Center HIGH 8.2
CVE-2026-34327

Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over …

Mitigation only
Fix from $1,950 2026-05-07
Copilot Chat HIGH 7.5
CVE-2026-33111

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …

Mitigation only
Fix from $1,950 2026-05-07
Teams MEDIUM 6.5
CVE-2026-33823

Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $1,600 2026-05-07
365 Copilot Chat HIGH 7.5
CVE-2026-26129

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…

No fix yet
Fix from $1,950 2026-05-07
365 Copilot Chat HIGH 7.5
CVE-2026-26164

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…

No fix yet
Fix from $1,950 2026-05-07
Azure Machine Learning MEDIUM 6.1
CVE-2026-32207

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to per…

Mitigation only
Fix from $1,600 2026-05-07
Azure Iot Central CRITICAL 9.9
CVE-2026-21515

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-24
Go Ntlmssp HIGH 7.5
CVE-2026-32952

go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can caus…

Fix: 0.1.1+
Fix from $1,950 2026-04-24
Entra Id CRITICAL 10.0
CVE-2026-35431

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

Mitigation only
Fix from $2,300 2026-04-23
Bing CRITICAL 9.8
CVE-2026-33819

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-04-23
365 Copilot CRITICAL 9.3
CVE-2026-33102

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-23
Dynamics 365 HIGH 7.5
CVE-2026-32210

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

Mitigation only
Fix from $1,950 2026-04-23