Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-23652 Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execu… Power Pages Mitigation only Fix from $2,3002026-05-22 HIGH 7.7 CVE-2026-26147 Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. Azure Stack Hci Mitigation only Fix from $1,9502026-05-22 HIGH 7.5 CVE-2026-23663 Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. Global Secure Access No fix yet Fix from $1,9502026-05-22 HIGH 8.1 CVE-2026-45584 Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. Malware Protection Engine 1.1.26040.8+ Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-45498 KEVEPSS 63% Microsoft Defender Denial of Service Vulnerability Defender Antimalware Platform 4.18.26040.7+ Fix from $1,9502026-05-20 HIGH 7.8 CVE-2026-42834 Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. Windows Admin Center 0.72.0.0+ Fix from $1,9502026-05-20 HIGH 7.8 CVE-2026-41091 KEVEPSS 10% Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. Malware Protection Engine 1.1.26040.8+ Fix from $1,9502026-05-20 MEDIUM 6.8 CVE-2026-45585 Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this… Windows 11 24h2 No fix yet Fix from $1,6002026-05-20 CRITICAL 9.8 CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Edge Chromium 148.0.3967.70+ Fix from $2,3002026-05-18 MEDIUM 6.1 CVE-2026-45494 Microsoft Edge (Chromium-based) Spoofing Vulnerability Edge Chromium 148.0.3967.70+ Fix from $1,6002026-05-18 MEDIUM 5.4 CVE-2026-45492 Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. Edge Chromium 148.0.3967.70+ Fix from $1,6002026-05-18 CRITICAL 10.0 CVE-2026-42822 Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. Azure Local 2604.2.25645+ Fix from $2,3002026-05-18 MEDIUM 6.1 CVE-2026-42897 KEVEPSS 70% Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to … Exchange Server 15.02.2562.043+ Fix from $1,6002026-05-14 HIGH 7.4 CVE-2026-41615 Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a … Authenticator 6.8.47 / 6.2605.2973+ Fix from $1,9502026-05-14 CRITICAL 9.9 CVE-2026-42898 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over … Dynamics 365 9.1.45.11+ Fix from $2,3002026-05-12 HIGH 7.8 CVE-2026-42896 Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.8457 / 10.0.26100.32860+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-42893 Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tamper… Outlook 5.2617.1+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-42899 Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network. .net 8.0.27 / 9.0.16+ Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2026-42891 User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing … Edge Chromium 148.0.3967.55+ Fix from $1,6002026-05-12 MEDIUM 5.4 CVE-2026-42838 Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unaut… Edge Chromium 148.0.3967.55+ Fix from $1,6002026-05-12 CRITICAL 9.9 CVE-2026-42823 Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. Azure Logic Apps Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-42833 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over … Dynamics 365 9.1.45.11+ Fix from $2,3002026-05-12 HIGH 7.8 CVE-2026-42831 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Copilot 16.0.19822.20190+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-42825 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2026-42830 Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. Azure Monitor Agent 1.42.0+ Fix from $1,6002026-05-12 MEDIUM 5.5 CVE-2026-42832 Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. Excel 16.0.19822.20190+ Fix from $1,6002026-05-12 HIGH 8.8 CVE-2026-41613 Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. Visual Studio Code 1.119.1+ Fix from $1,9502026-05-12 MEDIUM 6.2 CVE-2026-41614 Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally. 365 Copilot 19.2604.43111.0+ Fix from $1,6002026-05-12 MEDIUM 5.5 CVE-2026-41612 Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. Live Preview 0.4.19+ Fix from $1,6002026-05-12 HIGH 8.8 CVE-2026-41109 Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unau… Visual Studio Code 1.119.1+ Fix from $1,9502026-05-12