Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-50512 Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.21.6.0+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-50511 Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.21.6.0+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-50508EPSS 9% Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. Windows 10 1607 10.0.14393.9234 / 10.0.19045.7417+ Fix from $1,9502026-06-09 MEDIUM 6.8 CVE-2026-50507EPSS 5% Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,6002026-06-09 HIGH 7.8 CVE-2026-49161 Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. Pc Manager 3.21.6.0+ Fix from $1,9502026-06-09 HIGH 7.9 CVE-2026-48576 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.9 CVE-2026-48578 Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.9 CVE-2026-48575 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-48574 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-48583 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-49160EPSS 54% Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.9 CVE-2026-48573 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.9 CVE-2026-48568 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.9 CVE-2026-48570 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-48565 Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. Windows Narrator Braille Mitigation only Fix from $1,9502026-06-09 MEDIUM 5.5 CVE-2026-48566 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.8390 / 10.0.26100.32772+ Fix from $1,6002026-06-09 MEDIUM 5.5 CVE-2026-48569 Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. Visual Studio Code 1.123.2+ Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-48563 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Windows 10 1809 10.0.17763.8880 / 10.0.19044.7417+ Fix from $1,9502026-06-09 MEDIUM 5.4 CVE-2026-48560 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 HIGH 7.9 CVE-2026-47656 Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 CRITICAL 9.8 CVE-2026-47643 External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. Azure Stack Edge 3.3.2604.3097+ Fix from $2,3002026-06-09 HIGH 8.8 CVE-2026-47653 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 8.2 CVE-2026-47652 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. Windows 11 23h2 10.0.20348.5256 / 10.0.22631.7219+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-47654 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Windows Server 2016 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.0 CVE-2026-47648 Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 MEDIUM 5.4 CVE-2026-47641 Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 MEDIUM 5.4 CVE-2026-47640 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09 HIGH 8.4 CVE-2026-47635 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. Office 2024 Mitigation only Fix from $1,9502026-06-09 HIGH 8.0 CVE-2026-47298 Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20384+ Fix from $1,9502026-06-09 MEDIUM 5.4 CVE-2026-47634 Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorize… Sharepoint Server 16.0.19725.20384+ Fix from $1,6002026-06-09