Export limit exceeded: 26444 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (26444 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-69400 | 1 Microsoft | 1 Azure Logic Apps | 2026-08-24 | 9.6 Critical |
| Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-68789 | 1 Microsoft | 1 Azure Sql Database | 2026-08-24 | 9.9 Critical |
| Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-68782 | 1 Microsoft | 1 Azure Sql Database | 2026-08-24 | 9.9 Critical |
| Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-66309 | 1 Microsoft | 1 Azure Sql Database | 2026-08-24 | 9.1 Critical |
| Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-65801 | 1 Microsoft | 1 Exchange Online | 2026-08-24 | 10 Critical |
| Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-66800 | 1 Microsoft | 1 Azure Data Factory | 2026-08-24 | 8.6 High |
| Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-62834 | 1 Microsoft | 1 Azure Data Factory | 2026-08-24 | 9.3 Critical |
| Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-48567 | 1 Microsoft | 2 .azure Horizondb, Azure Horizondb | 2026-08-24 | 10 Critical |
| Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-65795 | 1 Microsoft | 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more | 2026-08-22 | 6.7 Medium |
| Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-62727 | 1 Microsoft | 26 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 23 more | 2026-08-21 | 7 High |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69502 | 1 Microsoft | 1 Azure Sql Database | 2026-08-21 | 10 Critical |
| Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69855 | 1 Microsoft | 1 Microsoft Copilot In Azure | 2026-08-21 | 7.7 High |
| Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-69419 | 1 Microsoft | 1 Azure Data Manager For Energy | 2026-08-21 | 8.5 High |
| Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-63509 | 1 Microsoft | 1 Microsoft Fabric | 2026-08-21 | 9.9 Critical |
| Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-70105 | 1 Microsoft | 12 365 Apps, Microsoft 365 Apps For Enterprise, Microsoft Office Ltsc For Mac 2021 and 9 more | 2026-08-21 | 6.5 Medium |
| Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-76037 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-20 | 8.4 High |
| Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High) | ||||
| CVE-2026-54117 | 1 Microsoft | 7 Microsoft Sql Server 2025 (cu 2), Microsoft Sql Server 2025 For X64-based Systems (gdr), Sql Server 2016 and 4 more | 2026-08-20 | 9.8 Critical |
| Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-54118 | 1 Microsoft | 15 Microsoft Sql Server 2016 Service Pack 3 (gdr), Microsoft Sql Server 2016 Service Pack 3 Azure Connect Feature Pack, Microsoft Sql Server 2017 (cu 31) and 12 more | 2026-08-20 | 9.8 Critical |
| Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-71331 | 1 Microsoft | 6 Windows 10 1809, Windows Server 2019, Windows Server 2019 (server Core Installation) and 3 more | 2026-08-20 | 8.1 High |
| Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-66802 | 1 Microsoft | 8 Windows 10 1809, Windows 11 26h1, Windows 11 26h1 and 5 more | 2026-08-20 | 8.1 High |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. | ||||
