Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2026-32218 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. Windows 10 21h2 10.0.19044.7184 / 10.0.19045.7184+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-32214 Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-32215 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. Windows 10 1809 10.0.17763.8644 / 10.0.19044.7184+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-32216 Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally. Windows 11 26h1 10.0.28000.1836+ Fix from $1,6002026-04-14 HIGH 7.5 CVE-2026-32203 Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network. .net 8.0.26 / 9.0.15+ Fix from $1,9502026-04-14 MEDIUM 6.5 CVE-2026-32201 KEVEPSS 23% Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20210+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-32212 Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform… Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 HIGH 7.8 CVE-2026-32197 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20113+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32198 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20113+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32199 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20113+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32200 Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-04-14 MEDIUM 6.1 CVE-2026-32196 Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perfo… Windows Admin Center 2511+ Fix from $1,6002026-04-14 HIGH 8.4 CVE-2026-32190 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32192 Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. Azure Monitor Agent 1.41.0+ Fix from $1,9502026-04-14 HIGH 7.0 CVE-2026-32195 Stack-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 11 26h1 10.0.28000.1836+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32189 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-04-14 HIGH 7.1 CVE-2026-32188 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 365 Apps Mitigation only Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32184 Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally. Hpc Pack 6.3.8355+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32176 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6485.1 / 13.0.7080.1+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32183 Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execu… Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 HIGH 7.5 CVE-2026-32178 Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network. .net 8.0.26 / 9.0.15+ Fix from $1,9502026-04-14 MEDIUM 5.5 CVE-2026-32181 Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally. Windows 10 21h2 10.0.19044.7184 / 10.0.19045.7184+ Fix from $1,6002026-04-14 HIGH 8.8 CVE-2026-32171 Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. Azure Logic Apps Mitigation only Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32165 Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8644 / 10.0.19044.7184+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32167 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6485.1 / 13.0.7080.1+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32168 Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. Azure Monitor Agent 1.35.9+ Fix from $1,9502026-04-14 HIGH 8.4 CVE-2026-32162 Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8644 / 10.0.19044.7184+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32163 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attac… Windows 10 1809 10.0.17763.8644 / 10.0.19044.7184+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-32164 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attac… Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 HIGH 8.8 CVE-2026-32157 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Remote Desktop Client 2.0.1070.0 / 10.0.14393.9060+ Fix from $1,9502026-04-14