Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Power Apps CRITICAL 9.0
CVE-2026-26149

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a networ…

Fix: 3.26032.10.0+
Fix from $2,300 2026-04-14
Powershell HIGH 7.8
CVE-2026-26143

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

Fix: 7.4.14 / 7.5.5+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.1
CVE-2026-26151

Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 11 23h2 HIGH 7.0
CVE-2026-25184

Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an …

Fix: 10.0.22631.6936 / 10.0.25398.2274+
Fix from $1,950 2026-04-14
365 Apps HIGH 7.8
CVE-2026-23657

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-04-14
.net Framework HIGH 7.5
CVE-2026-23666

Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.

Mitigation only
Fix from $1,950 2026-04-14
Github Copilot Chat MEDIUM 6.5
CVE-2026-23653

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized att…

Fix: 0.37.3+
Fix from $1,600 2026-04-14
Windows 10 1607 MEDIUM 5.7
CVE-2026-23670

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature local…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 1809 HIGH 7.8
CVE-2026-20930

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,950 2026-04-14
Sharepoint Server MEDIUM 5.4
CVE-2026-20945EPSS 25%

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19725.20210+
Fix from $1,600 2026-04-14
Windows 10 1607 MEDIUM 6.7
CVE-2026-0390

Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 1809 MEDIUM 5.5
CVE-2026-20806

Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,600 2026-04-14
Edge MEDIUM 5.4
CVE-2026-33119

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing …

Fix: 147.0.3912.60+
Fix from $1,600 2026-04-10
Symcrypt MEDIUM 6.1
CVE-2026-35199

SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptXmssSign function passes …

Fix: 103.11.0+
Fix from $1,600 2026-04-06
Bing CRITICAL 9.8
CVE-2026-32186

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-03
Azure Kubernetes Service CRITICAL 9.8
CVE-2026-33105

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Databricks CRITICAL 9.8
CVE-2026-33107

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Ai Foundry CRITICAL 9.8
CVE-2026-32213

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Custom Locations Resource Provider HIGH 8.8
CVE-2026-26135

Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a networ…

Mitigation only
Fix from $1,950 2026-04-03
Azure Sre Agent HIGH 7.5
CVE-2026-32173

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-04-03
Azure Web Apps HIGH 7.5
CVE-2026-32211

Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-04-03
Xml Notepad MEDIUM 6.5
CVE-2026-34401

XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, X…

Fix: 2.9.0.21+
Fix from $1,600 2026-03-31
Bing Images CRITICAL 9.8
CVE-2026-32194

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execu…

No fix yet
Fix from $2,300 2026-03-19
Azure Cloud Shell CRITICAL 9.8
CVE-2026-32169

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-03-19
Bing Images CRITICAL 9.8
CVE-2026-32191

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t…

Mitigation only
Fix from $2,300 2026-03-19
Purview CRITICAL 10.0
CVE-2026-26138

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-03-19
365 Copilot Chat CRITICAL 9.9
CVE-2026-26137

Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-03-19
Purview HIGH 8.6
CVE-2026-26139

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-03-19
Copilot HIGH 7.5
CVE-2026-26136

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose …

Mitigation only
Fix from $1,950 2026-03-19
Bing HIGH 7.5
CVE-2026-26120

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.

No fix yet
Fix from $1,950 2026-03-19