Vulnerabilities (CVE)

Total 403775 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-26132 1 Microsoft 9 Windows 10 21h2, Windows 10 22h2, Windows 11 23h2 and 6 more 2026-06-17 N/A 7.8 HIGH
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-26131 2 Linux, Microsoft 2 Linux Kernel, .net 2026-06-17 N/A 7.8 HIGH
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-26129 1 Microsoft 1 365 Copilot Chat 2026-06-17 N/A 7.5 HIGH
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-26128 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more 2026-06-17 N/A 7.8 HIGH
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
CVE-2026-26127 3 Apple, Linux, Microsoft 5 Macos, Linux Kernel, .net and 2 more 2026-06-17 N/A 7.5 HIGH
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-26125 1 Microsoft 1 Payment Orchestrator Service 2026-06-17 N/A 8.6 HIGH
Payment Orchestrator Service Elevation of Privilege Vulnerability
CVE-2026-26124 1 Microsoft 1 Aci Confidential Containers 2026-06-17 N/A 6.7 MEDIUM
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
CVE-2026-26123 1 Microsoft 1 Authenticator 2026-06-17 N/A 5.5 MEDIUM
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
CVE-2026-26122 1 Microsoft 1 Aci Confidential Containers 2026-06-17 N/A 6.5 MEDIUM
Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
CVE-2026-26121 1 Microsoft 1 Azure Iot Explorer 2026-06-17 N/A 7.5 HIGH
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-26120 1 Microsoft 1 Bing 2026-06-17 N/A 6.5 MEDIUM
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.
CVE-2026-26119 1 Microsoft 1 Windows Admin Center 2026-06-17 N/A 8.8 HIGH
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-26118 1 Microsoft 1 Azure Mcp Server 2026-06-17 N/A 8.8 HIGH
Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-26117 1 Microsoft 1 Arc Enabled Servers Azure Connected Machine Agent 2026-06-17 N/A 7.8 HIGH
Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-26116 1 Microsoft 5 Sql Server 2016, Sql Server 2017, Sql Server 2019 and 2 more 2026-06-17 N/A 8.8 HIGH
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-26115 1 Microsoft 5 Sql Server 2016, Sql Server 2017, Sql Server 2019 and 2 more 2026-06-17 N/A 8.8 HIGH
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-26114 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 8.8 HIGH
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-26113 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 8.4 HIGH
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-26112 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2026-06-17 N/A 7.8 HIGH
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-26111 1 Microsoft 5 Windows Server 2012, Windows Server 2016, Windows Server 2019 and 2 more 2026-06-17 N/A 8.0 HIGH
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.