Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-24307 Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. 365 Copilot Mitigation only Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2026-24305 Azure Entra ID Elevation of Privilege Vulnerability Entra Id No fix yet Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-24306 Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. Azure Front Door No fix yet Fix from $2,3002026-01-22 CRITICAL 9.8 CVE-2026-21227 Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile… Azure Logic Apps Mitigation only Fix from $2,3002026-01-22 HIGH 7.5 CVE-2026-21520 Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through … Copilot Studio Mitigation only Fix from $1,9502026-01-22 HIGH 7.4 CVE-2026-21521 Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network. 365 Word Copilot Mitigation only Fix from $1,9502026-01-22 HIGH 7.4 CVE-2026-21524 Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a netw… Azure Data Explorer No fix yet Fix from $1,9502026-01-22 MEDIUM 6.1 CVE-2026-21264 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform … Account Mitigation only Fix from $1,6002026-01-22 HIGH 8.0 CVE-2026-20960 Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. Power Apps 3.25121+ Fix from $1,9502026-01-16 HIGH 7.1 CVE-2026-21223 Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. Edge Chromium 144.0.3719.82+ Fix from $1,9502026-01-16 HIGH 7.5 CVE-2026-21226 Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. Azure Core Shared Client Library 1.38.0+ Fix from $1,9502026-01-13 MEDIUM 6.4 CVE-2026-21265 Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices contain… Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 CRITICAL 9.8 CVE-2026-20963 KEVEPSS 32% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20442+ Fix from $2,3002026-01-13 HIGH 7.8 CVE-2026-21224 Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. Azure Connected Machine Agent 1.60+ Fix from $1,9502026-01-13 HIGH 7.5 CVE-2026-20965 Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally. Windows Admin Center 0.70.0.0+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-21219 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. Windows Software Development Kit 10.0.26100.7463+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-21221 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a… Windows 11 24h2 10.0.26100.7623 / 10.0.26100.32230+ Fix from $1,9502026-01-13 HIGH 8.4 CVE-2026-20953 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20955 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20083+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20956 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20957 Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20083+ Fix from $1,9502026-01-13 MEDIUM 5.4 CVE-2026-20958 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. Sharepoint Server 16.0.19127.20442+ Fix from $1,6002026-01-13 MEDIUM 5.4 CVE-2026-20959EPSS 7% Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19127.20442+ Fix from $1,6002026-01-13 HIGH 8.8 CVE-2026-20947EPSS 19% Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to … Sharepoint Server 16.0.19127.20442+ Fix from $1,9502026-01-13 HIGH 8.4 CVE-2026-20952 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 365 Apps No fix yet Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20946 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20948 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. 365 Apps Mitigation only Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20949 Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. 365 Apps No fix yet Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20950 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 365 Apps 16.0.10417.20083+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20951 Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. Sharepoint Server 16.0.19127.20442+ Fix from $1,9502026-01-13