Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

365 Copilot MEDIUM 5.3
CVE-2026-24299

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…

Mitigation only
Fix from $1,600 2026-03-19
Azure Data Factory HIGH 7.5
CVE-2026-23659

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a netwo…

No fix yet
Fix from $1,950 2026-03-19
Azure Devops CRITICAL 9.8
CVE-2026-23658

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-03-19
.net HIGH 7.5
CVE-2026-25667

ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by se…

Fix: 8.0.22 / 9.0.11+
Fix from $1,950 2026-03-19
365 Copilot HIGH 7.1
CVE-2026-26133

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Fix: 2.2.260210.21290750 / 2.106+
Fix from $1,950 2026-03-16
Edge Chromium MEDIUM 5.0
CVE-2026-0385

Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

Fix: 146.0.3856.59+
Fix from $1,600 2026-03-16
Authenticator MEDIUM 5.5
CVE-2026-26123

Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.

Fix: 6.8.40 / 6.2511.7533+
Fix from $1,600 2026-03-10
Azure Ad Ssh Login Extension For Linux HIGH 8.1
CVE-2026-26148

External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.

Fix: 1.0.033370002+
Fix from $1,950 2026-03-10
.net HIGH 7.8
CVE-2026-26131

Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.

Fix: 10.0.4+
Fix from $1,950 2026-03-10
Windows 10 21h2 HIGH 7.8
CVE-2026-26132

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7058 / 10.0.19045.7058+
Fix from $1,950 2026-03-10
365 Copilot HIGH 7.8
CVE-2026-26134

Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

Fix: 16.0.19822.20000+
Fix from $1,950 2026-03-10
Azure Automation Hybrid Worker Windows Extension HIGH 7.8
CVE-2026-26141

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

Fix: 1.3.74+
Fix from $1,950 2026-03-10
Asp.net Core HIGH 7.5
CVE-2026-26130

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Fix: 8.0.25 / 9.0.14+
Fix from $1,950 2026-03-10
Azure Mcp Server HIGH 8.8
CVE-2026-26118

Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.

Fix: 2.0.0+
Fix from $1,950 2026-03-10
Arc Enabled Servers Azure Connected Machine Agent HIGH 7.8
CVE-2026-26117

Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges l…

Fix: 1.61+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-26128

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Azure Iot Explorer HIGH 7.5
CVE-2026-26121

Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.

Fix: 0.15.14+
Fix from $1,950 2026-03-10
.net HIGH 7.5
CVE-2026-26127

Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.

Fix: 9.0.14 / 10.0.4+
Fix from $1,950 2026-03-10
Sharepoint Server HIGH 8.8
CVE-2026-26114

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $1,950 2026-03-10
Sql Server 2016 HIGH 8.8
CVE-2026-26115

Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.

Fix: 13.0.6480.4 / 13.0.7075.5+
Fix from $1,950 2026-03-10
Sql Server 2016 HIGH 8.8
CVE-2026-26116

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6480.4 / 13.0.7075.5+
Fix from $1,950 2026-03-10
365 Apps HIGH 7.8
CVE-2026-26113

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.19725.20076+
Fix from $1,950 2026-03-10
Windows Server 2012 HIGH 8.0
CVE-2026-26111

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

Fix: 6.2.9200.25973 / 10.0.14393.8957+
Fix from $1,950 2026-03-10
365 Apps HIGH 7.8
CVE-2026-26108

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20102+
Fix from $1,950 2026-03-10
365 Apps HIGH 7.8
CVE-2026-26109

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20102+
Fix from $1,950 2026-03-10
365 Apps HIGH 7.8
CVE-2026-26110

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Fix: 16.0.19822.20000+
Fix from $1,950 2026-03-10
365 Apps HIGH 7.8
CVE-2026-26112

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20102+
Fix from $1,950 2026-03-10
Sharepoint Server CRITICAL 9.3
CVE-2026-26105

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20076+
Fix from $2,300 2026-03-10
Sharepoint Server HIGH 8.8
CVE-2026-26106

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.19725.20076+
Fix from $1,950 2026-03-10
365 Apps HIGH 7.8
CVE-2026-26107

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20102+
Fix from $1,950 2026-03-10