Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

365 Apps MEDIUM 5.5
CVE-2026-63517

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

No fix yet
Fix from $4,000 2026-08-11
Exchange Server HIGH 8.8
CVE-2026-62913

Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

Fix: 15.02.2562.046+
Fix from $4,900 2026-08-11
Exchange Server HIGH 8.0
CVE-2026-62911

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Fix: 15.02.2562.046+
Fix from $4,900 2026-08-11
Exchange Server MEDIUM 6.5
CVE-2026-62912

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.

Fix: 15.02.2562.046+
Fix from $4,000 2026-08-11
Exchange Server MEDIUM 6.5
CVE-2026-62915

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

Fix: 15.02.2562.046+
Fix from $4,000 2026-08-11
Sharepoint Server MEDIUM 6.5
CVE-2026-63512

Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.

Fix: 16.0.19725.20522+
Fix from $4,000 2026-08-11
Exchange Server MEDIUM 5.4
CVE-2026-62914

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to pe…

Fix: 15.02.2562.046+
Fix from $4,000 2026-08-11
Exchange Server HIGH 8.8
CVE-2026-62910

Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over…

Fix: 15.02.2562.046+
Fix from $4,900 2026-08-11
Visual Studio 2022 HIGH 7.8
CVE-2026-62909

Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.

Fix: 8.0.30 / 9.0.19+
Fix from $4,900 2026-08-11
Visual Studio 2022 HIGH 7.5
CVE-2026-62901

Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.

Fix: 8.0.30 / 9.0.19+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.0
CVE-2026-62908

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to…

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Visual Studio 2022 MEDIUM 6.5
CVE-2026-62902

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

Fix: 8.0.30 / 9.0.19+
Fix from $4,000 2026-08-11
Visual Studio 2022 MEDIUM 5.9
CVE-2026-62899

Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature…

Fix: 8.0.30 / 9.0.19+
Fix from $4,000 2026-08-11
Visual Studio 2022 MEDIUM 5.9
CVE-2026-62900

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

Fix: 8.0.30 / 9.0.19+
Fix from $4,000 2026-08-11
Windows 10 1607 CRITICAL 9.8
CVE-2026-62893

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $5,750 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62894

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Visual Studio 2022 HIGH 7.5
CVE-2026-62898

Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.

Fix: 8.0.30 / 9.0.19+
Fix from $4,900 2026-08-11
.net Framework HIGH 7.0
CVE-2026-62897

Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

Fix: 8.0.30 / 9.0.19+
Fix from $4,900 2026-08-11
Windows 10 1809 HIGH 7.0
CVE-2026-62892

Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 8.1
CVE-2026-62889

Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 21h2 HIGH 7.8
CVE-2026-62888

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7663 / 10.0.19045.7663+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62890

Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62885

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Visual Studio 2022 HIGH 7.8
CVE-2026-62886

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

Fix: 8.0.30 / 9.0.19+
Fix from $4,900 2026-08-11
Windows 10 1607 MEDIUM 6.7
CVE-2026-62881

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,000 2026-08-11
Windows 10 1607 MEDIUM 6.7
CVE-2026-62883

Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,000 2026-08-11
Windows 10 1607 MEDIUM 5.5
CVE-2026-62887

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,000 2026-08-11
Windows 10 1607 CRITICAL 9.8
CVE-2026-62878

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $5,750 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62876

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62877

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11