Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 21h2 MEDIUM 5.5
CVE-2026-32218

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.19044.7184 / 10.0.19045.7184+
Fix from $1,600 2026-04-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-32214

Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 1809 MEDIUM 5.5
CVE-2026-32215

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,600 2026-04-14
Windows 11 26h1 MEDIUM 5.5
CVE-2026-32216

Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.

Fix: 10.0.28000.1836+
Fix from $1,600 2026-04-14
.net HIGH 7.5
CVE-2026-32203

Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.

Fix: 8.0.26 / 9.0.15+
Fix from $1,950 2026-04-14
Sharepoint Server MEDIUM 6.5
CVE-2026-32201 KEVEPSS 23%

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20210+
Fix from $1,600 2026-04-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-32212

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
365 Apps HIGH 7.8
CVE-2026-32197

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20113+
Fix from $1,950 2026-04-14
365 Apps HIGH 7.8
CVE-2026-32198

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20113+
Fix from $1,950 2026-04-14
365 Apps HIGH 7.8
CVE-2026-32199

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20113+
Fix from $1,950 2026-04-14
365 Apps HIGH 7.8
CVE-2026-32200

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
Windows Admin Center MEDIUM 6.1
CVE-2026-32196

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perfo…

Fix: 2511+
Fix from $1,600 2026-04-14
365 Apps HIGH 8.4
CVE-2026-32190

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
Azure Monitor Agent HIGH 7.8
CVE-2026-32192

Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.41.0+
Fix from $1,950 2026-04-14
Windows 11 26h1 HIGH 7.0
CVE-2026-32195

Stack-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.28000.1836+
Fix from $1,950 2026-04-14
365 Apps HIGH 7.8
CVE-2026-32189

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
365 Apps HIGH 7.1
CVE-2026-32188

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Mitigation only
Fix from $1,950 2026-04-14
Hpc Pack HIGH 7.8
CVE-2026-32184

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally.

Fix: 6.3.8355+
Fix from $1,950 2026-04-14
Sql Server 2016 HIGH 7.8
CVE-2026-32176

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6485.1 / 13.0.7080.1+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-32183

Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execu…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
.net HIGH 7.5
CVE-2026-32178

Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.

Fix: 8.0.26 / 9.0.15+
Fix from $1,950 2026-04-14
Windows 10 21h2 MEDIUM 5.5
CVE-2026-32181

Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.

Fix: 10.0.19044.7184 / 10.0.19045.7184+
Fix from $1,600 2026-04-14
Azure Logic Apps HIGH 8.8
CVE-2026-32171

Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-04-14
Windows 10 1809 HIGH 7.8
CVE-2026-32165

Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,950 2026-04-14
Sql Server 2016 HIGH 7.8
CVE-2026-32167

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6485.1 / 13.0.7080.1+
Fix from $1,950 2026-04-14
Azure Monitor Agent HIGH 7.8
CVE-2026-32168

Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.35.9+
Fix from $1,950 2026-04-14
Windows 10 1809 HIGH 8.4
CVE-2026-32162

Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,950 2026-04-14
Windows 10 1809 HIGH 7.8
CVE-2026-32163

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attac…

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-32164

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attac…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Remote Desktop Client HIGH 8.8
CVE-2026-32157

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 2.0.1070.0 / 10.0.14393.9060+
Fix from $1,950 2026-04-14