Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-23655 Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network. Confidential Sidecar Containers 2.12+ Fix from $1,6002026-02-10 CRITICAL 9.8 CVE-2026-21531 Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network. Azure Conversation Authoring Client Library Mitigation only Fix from $2,3002026-02-10 HIGH 8.8 CVE-2026-21537 Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adj… Defender For Endpoint Mitigation only Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21533 KEV Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-21527EPSS 8% User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a… Exchange Server 15.02.2562.037+ Fix from $1,6002026-02-10 MEDIUM 6.5 CVE-2026-21528 Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. Azure Iot Explorer 0.15.13+ Fix from $1,6002026-02-10 MEDIUM 5.4 CVE-2026-21529 Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spo… Azure Hdinsight 5.1+ Fix from $1,6002026-02-10 HIGH 8.8 CVE-2026-21518 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized a… Visual Studio Code 1.109.2+ Fix from $1,9502026-02-10 HIGH 8.0 CVE-2026-21523 Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. Visual Studio Code 1.109.2+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21519 KEV Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2026-21517 Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally. Windows App 11.3.2+ Fix from $1,9502026-02-10 MEDIUM 6.7 CVE-2026-21522 Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate… Confcom 1.2.8+ Fix from $1,6002026-02-10 MEDIUM 6.2 CVE-2026-21525 KEV Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,6002026-02-10 HIGH 8.8 CVE-2026-21510 KEVEPSS 26% Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 8.8 CVE-2026-21513 KEVEPSS 15% Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21514 KEV Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. 365 Apps Mitigation only Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21516 Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code… Github Copilot 1.5.63-243+ Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-21511 Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. 365 Apps 16.0.19127.20518+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2026-21508 Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-21512 Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network. Azure Devops Server 2022.2.0+ Fix from $1,6002026-02-10 MEDIUM 5.5 CVE-2026-21261 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 365 Apps 16.0.10417.20097+ Fix from $1,6002026-02-10 HIGH 8.8 CVE-2026-21255 Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 8.8 CVE-2026-21256 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attack… Visual Studio 2022 17.14.26+ Fix from $1,9502026-02-10 HIGH 8.0 CVE-2026-21257 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker… Visual Studio 2022 17.14.26+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21259 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally. 365 Apps 16.0.10417.20097+ Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-21260 Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a net… 365 Apps 16.0.19127.20518+ Fix from $1,9502026-02-10 HIGH 7.0 CVE-2026-21253 Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 MEDIUM 5.5 CVE-2026-21258 Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 365 Apps 16.0.10417.20097+ Fix from $1,6002026-02-10 HIGH 7.8 CVE-2026-21246 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 HIGH 7.8 CVE-2026-21250 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.25398.2149 / 10.0.26100.7781+ Fix from $1,9502026-02-10