Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

365 Copilot HIGH 7.5
CVE-2026-24307

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-01-22
Entra Id CRITICAL 9.8
CVE-2026-24305

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-01-22
Azure Front Door CRITICAL 9.8
CVE-2026-24306

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-01-22
Azure Logic Apps CRITICAL 9.8
CVE-2026-21227

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…

Mitigation only
Fix from $2,300 2026-01-22
Copilot Studio HIGH 7.5
CVE-2026-21520

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through …

Mitigation only
Fix from $1,950 2026-01-22
365 Word Copilot HIGH 7.4
CVE-2026-21521

Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2026-01-22
Azure Data Explorer HIGH 7.4
CVE-2026-21524

Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a netw…

No fix yet
Fix from $1,950 2026-01-22
Account MEDIUM 6.1
CVE-2026-21264

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform …

Mitigation only
Fix from $1,600 2026-01-22
Power Apps HIGH 8.0
CVE-2026-20960

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

Fix: 3.25121+
Fix from $1,950 2026-01-16
Edge Chromium HIGH 7.1
CVE-2026-21223

Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

Fix: 144.0.3719.82+
Fix from $1,950 2026-01-16
Azure Core Shared Client Library HIGH 7.5
CVE-2026-21226

Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.

Fix: 1.38.0+
Fix from $1,950 2026-01-13
Windows 10 1607 MEDIUM 6.4
CVE-2026-21265

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices contain…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Sharepoint Server CRITICAL 9.8
CVE-2026-20963 KEVEPSS 32%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19127.20442+
Fix from $2,300 2026-01-13
Azure Connected Machine Agent HIGH 7.8
CVE-2026-21224

Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.60+
Fix from $1,950 2026-01-13
Windows Admin Center HIGH 7.5
CVE-2026-20965

Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.

Fix: 0.70.0.0+
Fix from $1,950 2026-01-13
Windows Software Development Kit HIGH 7.0
CVE-2026-21219

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Fix: 10.0.26100.7463+
Fix from $1,950 2026-01-13
Windows 11 24h2 HIGH 7.0
CVE-2026-21221

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a…

Fix: 10.0.26100.7623 / 10.0.26100.32230+
Fix from $1,950 2026-01-13
365 Apps HIGH 8.4
CVE-2026-20953

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20955

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20083+
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20956

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20957

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20083+
Fix from $1,950 2026-01-13
Sharepoint Server MEDIUM 5.4
CVE-2026-20958

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Fix: 16.0.19127.20442+
Fix from $1,600 2026-01-13
Sharepoint Server MEDIUM 5.4
CVE-2026-20959EPSS 7%

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19127.20442+
Fix from $1,600 2026-01-13
Sharepoint Server HIGH 8.8
CVE-2026-20947EPSS 19%

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to …

Fix: 16.0.19127.20442+
Fix from $1,950 2026-01-13
365 Apps HIGH 8.4
CVE-2026-20952

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

No fix yet
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20946

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20948

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

Mitigation only
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20949

Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

No fix yet
Fix from $1,950 2026-01-13
365 Apps HIGH 7.8
CVE-2026-20950

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Fix: 16.0.10417.20083+
Fix from $1,950 2026-01-13
Sharepoint Server HIGH 7.8
CVE-2026-20951

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

Fix: 16.0.19127.20442+
Fix from $1,950 2026-01-13