CVE List – Find High-Risk & Exploited Vulnerabilities

Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.

Assigner (CNA / source):[email protected] Remove this filter

Showing 120 of 1720 results
«« First « Prev Page 1 / 86 Next »
CVE Description Max CVSS EPSS % Published Updated
CVE-2026-47646 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network. 9.3 0.27% 2026-07-08 2026-07-09
CVE-2026-42901 Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. 10.0 0.30% 2026-05-22 2026-06-17
CVE-2026-40402 Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. 9.3 0.33% 2026-05-12 2026-06-17
CVE-2026-45602 No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. 9.1 0.37% 2026-06-09 2026-06-17
CVE-2026-21264 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network. 9.3 0.37% 2026-01-22 2026-06-17
CVE-2026-24303 Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. 9.6 0.39% 2026-04-23 2026-06-17
CVE-2026-33102 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 9.3 0.39% 2026-04-23 2026-06-17
CVE-2026-48582 Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. 9.6 0.40% 2026-06-19 2026-06-24
CVE-2025-55321 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network. 9.3 0.40% 2025-10-09 2026-06-17
CVE-2026-41090 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. 9.3 0.42% 2026-05-22 2026-06-17
CVE-2026-47647 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. 9.9 0.44% 2026-06-18 2026-06-25
CVE-2026-58289 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 9.0 0.44% 2026-07-03 2026-07-07
CVE-2026-42904 Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. 9.6 0.44% 2026-06-09 2026-06-17
CVE-2026-33843 Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. 9.1 0.47% 2026-05-22 2026-06-17
CVE-2026-33117 The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6. 9.1 0.48% 2026-05-12 2026-06-17
CVE-2026-47280 Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. 10.0 0.49% 2026-05-22 2026-06-17
CVE-2026-42822 Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. 10.0 0.49% 2026-05-18 2026-06-17
CVE-2026-24305 Azure Entra ID Elevation of Privilege Vulnerability 9.3 0.50% 2026-01-22 2026-06-17
CVE-2026-48584 Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. 9.9 0.50% 2026-06-19 2026-06-29
CVE-2026-35431 Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. 10.0 0.51% 2026-04-23 2026-06-17
«« First « Prev Page 1 / 86 Next »
cvelogic Threat Intelligence