Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1607 HIGH 7.8
CVE-2026-24291

Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate…

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 11 24h2 HIGH 8.8
CVE-2026-24283

Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.

Fix: 10.0.25398.2207 / 10.0.26100.7979+
Fix from $1,950 2026-03-10
Windows 10 1809 HIGH 7.8
CVE-2026-24287

External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8511 / 10.0.19044.7058+
Fix from $1,950 2026-03-10
365 Copilot HIGH 7.0
CVE-2026-24285

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 21h2 MEDIUM 6.8
CVE-2026-24288

Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack.

Fix: 10.0.19044.7058 / 10.0.19045.7058+
Fix from $1,600 2026-03-10
Windows 10 1607 MEDIUM 5.5
CVE-2026-24282

Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,600 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-23673

Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.5
CVE-2026-23674

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 8.8
CVE-2026-23669

Use after free in RPC Runtime allows an authorized attacker to execute code over a network.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.8
CVE-2026-23672

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.0
CVE-2026-23668

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized atta…

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows 10 1607 HIGH 7.0
CVE-2026-23671

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an auth…

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows Admin Center HIGH 7.8
CVE-2026-23660

Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.

Fix: 2.6.4+
Fix from $1,950 2026-03-10
Linux Diagnostic Extension HIGH 7.8
CVE-2026-23665

Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally.

Fix: 2.1.24+
Fix from $1,950 2026-03-10
Azure Iot Explorer HIGH 7.5
CVE-2026-23661

Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

Fix: 0.15.13+
Fix from $1,950 2026-03-10
Azure Iot Explorer HIGH 7.5
CVE-2026-23662

Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

Fix: 0.15.13+
Fix from $1,950 2026-03-10
Azure Iot Explorer HIGH 7.5
CVE-2026-23664

Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information ove…

Fix: 0.15.13+
Fix from $1,950 2026-03-10
Windows 10 1809 HIGH 7.0
CVE-2026-23667

Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8511 / 10.0.19044.7058+
Fix from $1,950 2026-03-10
Zero Shot Scfoundation HIGH 8.8
CVE-2026-23654

Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.

Fix: 0.1.1+
Fix from $1,950 2026-03-10
Windows App MEDIUM 5.9
CVE-2026-23656

Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.

Fix: 2.0.964.0+
Fix from $1,600 2026-03-10
Sql Server 2016 HIGH 8.8
CVE-2026-21262

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Fix: 13.0.6480.4 / 13.0.7075.5+
Fix from $1,950 2026-03-10
System Center Operations Manager HIGH 8.8
CVE-2026-20967

Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-03-10
Payment Orchestrator Service CRITICAL 9.8
CVE-2026-26125

Payment Orchestrator Service Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-03-05
Aci Confidential Containers MEDIUM 6.7
CVE-2026-23651

Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,600 2026-03-05
Aci Confidential Containers MEDIUM 6.7
CVE-2026-26124

'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $1,600 2026-03-05
Aci Confidential Containers MEDIUM 6.5
CVE-2026-26122

Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $1,600 2026-03-05
Devices Pricing Program CRITICAL 9.8
CVE-2026-21536

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

No fix yet
Fix from $2,300 2026-03-05
Teams HIGH 7.5
CVE-2026-21535

Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-02-19
Semantic Kernel CRITICAL 9.9
CVE-2026-26030

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within t…

Fix: 1.39.4+
Fix from $2,300 2026-02-19
Windows Admin Center HIGH 8.8
CVE-2026-26119

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 2511+
Fix from $1,950 2026-02-17