Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Confidential Sidecar Containers MEDIUM 6.5
CVE-2026-23655

Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

Fix: 2.12+
Fix from $1,600 2026-02-10
Azure Conversation Authoring Client Library CRITICAL 9.8
CVE-2026-21531

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-02-10
Defender For Endpoint HIGH 8.8
CVE-2026-21537

Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adj…

Mitigation only
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.8
CVE-2026-21533 KEV

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Exchange Server MEDIUM 6.5
CVE-2026-21527EPSS 8%

User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a…

Fix: 15.02.2562.037+
Fix from $1,600 2026-02-10
Azure Iot Explorer MEDIUM 6.5
CVE-2026-21528

Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

Fix: 0.15.13+
Fix from $1,600 2026-02-10
Azure Hdinsight MEDIUM 5.4
CVE-2026-21529

Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spo…

Fix: 5.1+
Fix from $1,600 2026-02-10
Visual Studio Code HIGH 8.8
CVE-2026-21518

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized a…

Fix: 1.109.2+
Fix from $1,950 2026-02-10
Visual Studio Code HIGH 8.0
CVE-2026-21523

Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.

Fix: 1.109.2+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.8
CVE-2026-21519 KEV

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows App HIGH 7.0
CVE-2026-21517

Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.

Fix: 11.3.2+
Fix from $1,950 2026-02-10
Confcom MEDIUM 6.7
CVE-2026-21522

Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate…

Fix: 1.2.8+
Fix from $1,600 2026-02-10
Windows 10 1607 MEDIUM 6.2
CVE-2026-21525 KEV

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,600 2026-02-10
Windows 10 1607 HIGH 8.8
CVE-2026-21510 KEVEPSS 26%

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 8.8
CVE-2026-21513 KEVEPSS 15%

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
365 Apps HIGH 7.8
CVE-2026-21514 KEV

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.

Mitigation only
Fix from $1,950 2026-02-10
Github Copilot HIGH 7.8
CVE-2026-21516

Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code…

Fix: 1.5.63-243+
Fix from $1,950 2026-02-10
365 Apps HIGH 7.5
CVE-2026-21511

Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

Fix: 16.0.19127.20518+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.0
CVE-2026-21508

Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Azure Devops Server MEDIUM 6.5
CVE-2026-21512

Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.

Fix: 2022.2.0+
Fix from $1,600 2026-02-10
365 Apps MEDIUM 5.5
CVE-2026-21261

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Fix: 16.0.10417.20097+
Fix from $1,600 2026-02-10
Windows 10 1607 HIGH 8.8
CVE-2026-21255

Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Visual Studio 2022 HIGH 8.8
CVE-2026-21256

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attack…

Fix: 17.14.26+
Fix from $1,950 2026-02-10
Visual Studio 2022 HIGH 8.0
CVE-2026-21257

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker…

Fix: 17.14.26+
Fix from $1,950 2026-02-10
365 Apps HIGH 7.8
CVE-2026-21259

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.

Fix: 16.0.10417.20097+
Fix from $1,950 2026-02-10
365 Apps HIGH 7.5
CVE-2026-21260

Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a net…

Fix: 16.0.19127.20518+
Fix from $1,950 2026-02-10
Windows 10 1607 HIGH 7.0
CVE-2026-21253

Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
365 Apps MEDIUM 5.5
CVE-2026-21258

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Fix: 16.0.10417.20097+
Fix from $1,600 2026-02-10
Windows 10 1607 HIGH 7.8
CVE-2026-21246

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Windows 11 24h2 HIGH 7.8
CVE-2026-21250

Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

Fix: 10.0.25398.2149 / 10.0.26100.7781+
Fix from $1,950 2026-02-10