Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-69414 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "Shield… Malware Protection Engine No fix yet Fix from $4,9002026-08-14 HIGH 7.8 CVE-2026-50523 Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute … Powershell No fix yet Fix from $4,9002026-08-14 HIGH 8.3 CVE-2026-72970 Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium No fix yet Fix from $4,9002026-08-14 MEDIUM 5.4 CVE-2026-70339 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over… Edge Chromium No fix yet Fix from $4,0002026-08-11 MEDIUM 6.7 CVE-2026-65680 Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. Onedrive No fix yet Fix from $4,0002026-08-11 MEDIUM 5.5 CVE-2026-72971 Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized att… Windows 11 26h1 10.0.28000.2704+ Fix from $4,0002026-08-11 HIGH 8.1 CVE-2026-71331 Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execut… Windows 10 1809 No fix yet Fix from $4,9002026-08-11 HIGH 8.7 CVE-2026-70355 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-70346 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-70347 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-70354 Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. Visual Studio 2022 No fix yet Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-70348 Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26200.9106+ Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-70336 Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. Visual Studio Code 1.132.1+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-70337 Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. Powershell 7.4.19.0 / 7.5.10.0+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-70340 Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. Azure Cyclecloud No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-70335 Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unautho… Visual Studio Code 1.132.1+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-70338 Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locall… Powershell 7.4.19.0 / 7.5.10.0+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-70344 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-70345 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-70324 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-70326 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-70329 Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. 365 Apps No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-70330 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-70327 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 365 Apps No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-70328 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 365 Apps No fix yet Fix from $4,0002026-08-11 MEDIUM 5.5 CVE-2026-70323 Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. 365 Apps No fix yet Fix from $4,0002026-08-11 MEDIUM 5.5 CVE-2026-70325 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 365 Apps No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-70321 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20522+ Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-70316 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 365 Apps No fix yet Fix from $4,0002026-08-11 MEDIUM 5.5 CVE-2026-70317 Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. 365 Apps No fix yet Fix from $4,0002026-08-11