Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.0 CVE-2026-26149 Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a networ… Power Apps 3.26032.10.0+ Fix from $2,3002026-04-14 HIGH 7.8 CVE-2026-26143 Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. Powershell 7.4.14 / 7.5.5+ Fix from $1,9502026-04-14 HIGH 7.1 CVE-2026-26151 Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 HIGH 7.0 CVE-2026-25184 Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an … Windows 11 23h2 10.0.22631.6936 / 10.0.25398.2274+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-23657 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-04-14 HIGH 7.5 CVE-2026-23666 Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. .net Framework Mitigation only Fix from $1,9502026-04-14 MEDIUM 6.5 CVE-2026-23653 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized att… Github Copilot Chat 0.37.3+ Fix from $1,6002026-04-14 MEDIUM 5.7 CVE-2026-23670 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature local… Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 HIGH 7.8 CVE-2026-20930 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac… Windows 10 1809 10.0.17763.8644 / 10.0.19044.7184+ Fix from $1,9502026-04-14 MEDIUM 5.4 CVE-2026-20945EPSS 25% Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19725.20210+ Fix from $1,6002026-04-14 MEDIUM 6.7 CVE-2026-0390 Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-20806 Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally. Windows 10 1809 10.0.17763.8644 / 10.0.19044.7184+ Fix from $1,6002026-04-14 MEDIUM 5.4 CVE-2026-33119 User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing … Edge 147.0.3912.60+ Fix from $1,6002026-04-10 MEDIUM 6.1 CVE-2026-35199 SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptXmssSign function passes … Symcrypt 103.11.0+ Fix from $1,6002026-04-06 CRITICAL 9.8 CVE-2026-32186 Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. Bing No fix yet Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-33105 Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Azure Kubernetes Service Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-33107 Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. Azure Databricks Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-32213 Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. Azure Ai Foundry Mitigation only Fix from $2,3002026-04-03 HIGH 8.8 CVE-2026-26135 Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a networ… Azure Custom Locations Resource Provider Mitigation only Fix from $1,9502026-04-03 HIGH 7.5 CVE-2026-32173 Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. Azure Sre Agent Mitigation only Fix from $1,9502026-04-03 HIGH 7.5 CVE-2026-32211 Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network. Azure Web Apps Mitigation only Fix from $1,9502026-04-03 MEDIUM 6.5 CVE-2026-34401 XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, X… Xml Notepad 2.9.0.21+ Fix from $1,6002026-03-31 CRITICAL 9.8 CVE-2026-32194 Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execu… Bing Images No fix yet Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-32169 Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. Azure Cloud Shell Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-32191 Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t… Bing Images Mitigation only Fix from $2,3002026-03-19 CRITICAL 10.0 CVE-2026-26138 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. Purview Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.9 CVE-2026-26137 Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. 365 Copilot Chat No fix yet Fix from $2,3002026-03-19 HIGH 8.6 CVE-2026-26139 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. Purview No fix yet Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-26136 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose … Copilot Mitigation only Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-26120 Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network. Bing No fix yet Fix from $1,9502026-03-19