Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2026-48580 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 365 Apps 16.0.10417.20175+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-47642 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20175+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-47295 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6500.1 / 13.0.7095.1+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-47290 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Patch available Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-58644 KEVEPSS 45% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 HIGH 7.8 CVE-2026-58640 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 5.4 CVE-2026-58647 Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing ov… Power Bi Report Server 15.0.1121.120+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-58609 Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-58610 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-58618 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20175+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-58631 Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally. Windows Admin Center 2606+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-58635 Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elev… Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-58636 Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.21.6.0+ Fix from $1,9502026-07-14 MEDIUM 5.5 CVE-2026-58614 Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 8.1 CVE-2026-58595 Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network. Bing Search 33.4.440529002+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-58526 Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-58601 Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-58602 Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.8875 / 10.0.26100.33158+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-58608 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized … Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-58279 Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. Azure Cyclecloud 8.9.1+ Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-57979 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-57976 Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 8.8 CVE-2026-56169 Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. Windows Admin Center 2606+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-57969 Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. Azure Cyclecloud 8.9.1+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-57107 Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. Windows Admin Center 2606+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-56170 Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. .net 8.0.29 / 9.0.18+ Fix from $1,9502026-07-14 MEDIUM 6.8 CVE-2026-57097 Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 6.5 CVE-2026-56185 Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. Windows Admin Center 2511+ Fix from $1,6002026-07-14 CRITICAL 9.8 CVE-2026-56164 KEVEPSS 22% Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 HIGH 7.8 CVE-2026-55012 Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally. Malware Protection Engine 1.1.26060.3008+ Fix from $1,9502026-07-14