Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-24299 Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor… 365 Copilot Mitigation only Fix from $1,6002026-03-19 HIGH 7.5 CVE-2026-23659 Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a netwo… Azure Data Factory No fix yet Fix from $1,9502026-03-19 CRITICAL 9.8 CVE-2026-23658 Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. Azure Devops No fix yet Fix from $2,3002026-03-19 HIGH 7.5 CVE-2026-25667 ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by se… .net 8.0.22 / 9.0.11+ Fix from $1,9502026-03-19 HIGH 7.1 CVE-2026-26133 AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. 365 Copilot 2.2.260210.21290750 / 2.106+ Fix from $1,9502026-03-16 MEDIUM 5.0 CVE-2026-0385 Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability Edge Chromium 146.0.3856.59+ Fix from $1,6002026-03-16 MEDIUM 5.5 CVE-2026-26123 Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally. Authenticator 6.8.40 / 6.2511.7533+ Fix from $1,6002026-03-10 HIGH 8.1 CVE-2026-26148 External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally. Azure Ad Ssh Login Extension For Linux 1.0.033370002+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26131 Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally. .net 10.0.4+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26132 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.7058 / 10.0.19045.7058+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26134 Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. 365 Copilot 16.0.19822.20000+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26141 Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. Azure Automation Hybrid Worker Windows Extension 1.3.74+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-26130 Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. Asp.net Core 8.0.25 / 9.0.14+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-26118 Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. Azure Mcp Server 2.0.0+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26117 Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges l… Arc Enabled Servers Azure Connected Machine Agent 1.61+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26128 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-26121 Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network. Azure Iot Explorer 0.15.14+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-26127 Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. .net 9.0.14 / 10.0.4+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-26114 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server Mitigation only Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-26115 Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. Sql Server 2016 13.0.6480.4 / 13.0.7075.5+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-26116 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6480.4 / 13.0.7075.5+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26113 Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19725.20076+ Fix from $1,9502026-03-10 HIGH 8.0 CVE-2026-26111 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. Windows Server 2012 6.2.9200.25973 / 10.0.14393.8957+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26108 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20102+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26109 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20102+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26110 Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps 16.0.19822.20000+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26112 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20102+ Fix from $1,9502026-03-10 CRITICAL 9.3 CVE-2026-26105 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20076+ Fix from $2,3002026-03-10 HIGH 8.8 CVE-2026-26106 Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20076+ Fix from $1,9502026-03-10 HIGH 7.8 CVE-2026-26107 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20102+ Fix from $1,9502026-03-10