Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Power Apps HIGH 8.0
CVE-2026-32172

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2026-04-23
Purview Ediscovery CRITICAL 10.0
CVE-2026-26150

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-23
Partner Center CRITICAL 9.6
CVE-2026-24303

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-23
Kiota HIGH 7.8
CVE-2026-41134

Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnera…

Fix: 1.31.1+
Fix from $1,950 2026-04-22
Asp.net Core CRITICAL 9.1
CVE-2026-40372EPSS 11%

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

Fix: 10.0.7+
Fix from $2,300 2026-04-21
Windows 10 1607 HIGH 8.1
CVE-2026-33827

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to exec…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows Server 2012 HIGH 8.0
CVE-2026-33826

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Defender Antimalware Platform HIGH 7.8
CVE-2026-33825 KEVEPSS 7%

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Fix: 4.18.26030.3011+
Fix from $1,950 2026-04-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-33824 KEVEPSS 78%

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $2,300 2026-04-14
Sql Server 2016 HIGH 8.8
CVE-2026-33120

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

Fix: 13.0.6485.1 / 13.0.7080.1+
Fix from $1,950 2026-04-14
365 Apps MEDIUM 6.1
CVE-2026-33822

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Mitigation only
Fix from $1,600 2026-04-14
365 Apps HIGH 8.4
CVE-2026-33114

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
365 Apps HIGH 8.4
CVE-2026-33115

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
.net HIGH 7.5
CVE-2026-33116

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a …

Fix: 8.0.26 / 9.0.15+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-33104

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Dynamics 365 MEDIUM 5.5
CVE-2026-33103

Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.

Fix: 9.1.44.15+
Fix from $1,600 2026-04-14
Windows 11 24h2 HIGH 7.8
CVE-2026-33101

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

Fix: 10.0.25398.2274 / 10.0.26100.8246+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-33099

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.0
CVE-2026-33100

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
365 Apps HIGH 7.8
CVE-2026-33095

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-33098

Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 11 23h2 HIGH 7.5
CVE-2026-33096

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

Fix: 10.0.20348.5020 / 10.0.22631.6936+
Fix from $1,950 2026-04-14
.net Framework MEDIUM 5.9
CVE-2026-32226

Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny…

No fix yet
Fix from $1,600 2026-04-14
Windows 10 1607 HIGH 8.8
CVE-2026-32225

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 11 24h2 HIGH 8.4
CVE-2026-32221

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

Fix: 10.0.26100.8246 / 10.0.26100.32690+
Fix from $1,950 2026-04-14
Windows 11 24h2 HIGH 7.8
CVE-2026-32222

Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8246 / 10.0.26100.32690+
Fix from $1,950 2026-04-14
Windows 11 26h1 HIGH 7.0
CVE-2026-32224

Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.28000.1836+
Fix from $1,950 2026-04-14
Windows 11 24h2 MEDIUM 6.8
CVE-2026-32223

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

Fix: 10.0.26100.8246 / 10.0.26100.32690+
Fix from $1,600 2026-04-14
Windows 11 24h2 HIGH 7.0
CVE-2026-32219

Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8246 / 10.0.26100.32690+
Fix from $1,950 2026-04-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-32217

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14