Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.0 CVE-2026-48571 Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.22631.7376 / 10.0.26100.8875+ Fix from $1,9502026-07-14 HIGH 7.0 CVE-2026-48572 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to… Windows 11 23h2 10.0.22631.7376 / 10.0.26100.8875+ Fix from $1,9502026-07-14 HIGH 7.0 CVE-2026-49162 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.8875 / 10.0.26100.33158+ Fix from $1,9502026-07-14 CRITICAL 9.6 CVE-2026-48561 Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker … 365 Copilot Mitigation only Fix from $2,3002026-07-14 HIGH 8.8 CVE-2026-47632 Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network. Azure Connected Machine Agent Mitigation only Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-48564 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-45646 Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. Asp.net Core Odata 7.8.0 / 9.5.0+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-47296 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6500.1 / 13.0.7095.1+ Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-47282 Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. Visual Studio Code 1.128.1+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-45496 Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a secu… Visual Studio Code 1.128.1+ Fix from $1,6002026-07-14 CRITICAL 9.8 CVE-2026-42990 Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $2,3002026-07-14 HIGH 8.8 CVE-2026-42975 Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-42982 Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-44800 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack… Windows 11 23h2 10.0.22631.7376 / 10.0.26100.8875+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-44806 Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.1 CVE-2026-42900 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to e… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.0 CVE-2026-40400 Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-40378 Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny ser… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 5.5 CVE-2026-40422 Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-41087 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 6.5 CVE-2026-34348 Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-33842 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-34328 Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-34346 Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose informatio… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 MEDIUM 5.5 CVE-2026-34349 Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,6002026-07-14 HIGH 8.3 CVE-2026-58596 Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-12 HIGH 8.3 CVE-2026-58281 Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-11 MEDIUM 6.1 CVE-2026-47646 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker t… Dynamics 365 Customer Voice Mitigation only Fix from $1,6002026-07-09 HIGH 8.2 CVE-2026-58525 Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. Edge Chromium 150.0.4078.50+ Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-58523 Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. Edge Chromium 150.0.4078.48+ Fix from $1,6002026-07-03