Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-33837 Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-33838 Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 CRITICAL 9.9 CVE-2026-33821 Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. Dynamics 365 Customer Insights Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-33117 The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com… Azure Sdk For Java 4.10.6+ Fix from $2,3002026-05-12 HIGH 8.8 CVE-2026-33110 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20280+ Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-33112 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20280+ Fix from $1,9502026-05-12 HIGH 7.8 CVE-2026-32204 External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. Azure Monitor Agent 1.14.0+ Fix from $1,9502026-05-12 MEDIUM 5.5 CVE-2026-32185 Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally. Teams 1.0.0.2026092103+ Fix from $1,6002026-05-12 HIGH 7.3 CVE-2026-32177 Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. Visual Studio 2022 8.0.27 / 9.0.16+ Fix from $1,9502026-05-12 MEDIUM 6.7 CVE-2026-32170 Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,6002026-05-12 HIGH 7.5 CVE-2026-32161 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthor… Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 MEDIUM 6.7 CVE-2026-21530 Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,6002026-05-12 HIGH 8.1 CVE-2026-41105 Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. Azure Monitor Action Group Notification System Mitigation only Fix from $1,9502026-05-07 HIGH 7.5 CVE-2026-42826 Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. Azure Devops No fix yet Fix from $1,9502026-05-07 CRITICAL 10.0 CVE-2026-35435 Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. Azure Ai Foundry Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.9 CVE-2026-33109 Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. Azure Managed Instance For Apache Cassandra Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.6 CVE-2026-35428 Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s… Azure Cloud Shell Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.0 CVE-2026-33844 Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. Azure Managed Instance For Apache Cassandra Mitigation only Fix from $2,3002026-05-07 HIGH 8.2 CVE-2026-34327 Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over … Partner Center Mitigation only Fix from $1,9502026-05-07 HIGH 7.5 CVE-2026-33111 Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker … Copilot Chat Mitigation only Fix from $1,9502026-05-07 MEDIUM 6.5 CVE-2026-33823 Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. Teams No fix yet Fix from $1,6002026-05-07 HIGH 7.5 CVE-2026-26129 Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor… 365 Copilot Chat No fix yet Fix from $1,9502026-05-07 HIGH 7.5 CVE-2026-26164 Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor… 365 Copilot Chat No fix yet Fix from $1,9502026-05-07 MEDIUM 6.1 CVE-2026-32207 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to per… Azure Machine Learning Mitigation only Fix from $1,6002026-05-07 CRITICAL 9.9 CVE-2026-21515 Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. Azure Iot Central No fix yet Fix from $2,3002026-04-24 HIGH 7.5 CVE-2026-32952 go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can caus… Go Ntlmssp 0.1.1+ Fix from $1,9502026-04-24 CRITICAL 10.0 CVE-2026-35431 Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. Entra Id Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-33819 Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. Bing Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.3 CVE-2026-33102 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 365 Copilot Mitigation only Fix from $2,3002026-04-23 HIGH 7.5 CVE-2026-32210 Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. Dynamics 365 Mitigation only Fix from $1,9502026-04-23