Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.
Assigner (CNA / source):[email protected] Remove this filter
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2026-47646 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network. | 9.3 | 0.27% | 2026-07-08 | 2026-07-09 |
| CVE-2026-42901 | Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | 10.0 | 0.30% | 2026-05-22 | 2026-06-17 |
| CVE-2026-40402 | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | 9.3 | 0.33% | 2026-05-12 | 2026-06-17 |
| CVE-2026-45602 | No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. | 9.1 | 0.37% | 2026-06-09 | 2026-06-17 |
| CVE-2026-21264 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network. | 9.3 | 0.37% | 2026-01-22 | 2026-06-17 |
| CVE-2026-24303 | Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. | 9.6 | 0.39% | 2026-04-23 | 2026-06-17 |
| CVE-2026-33102 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | 9.3 | 0.39% | 2026-04-23 | 2026-06-17 |
| CVE-2026-48582 | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 9.6 | 0.40% | 2026-06-19 | 2026-06-24 |
| CVE-2025-55321 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network. | 9.3 | 0.40% | 2025-10-09 | 2026-06-17 |
| CVE-2026-41090 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | 9.3 | 0.42% | 2026-05-22 | 2026-06-17 |
| CVE-2026-47647 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. | 9.9 | 0.44% | 2026-06-18 | 2026-06-25 |
| CVE-2026-58289 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 9.0 | 0.44% | 2026-07-03 | 2026-07-07 |
| CVE-2026-42904 | Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. | 9.6 | 0.44% | 2026-06-09 | 2026-06-17 |
| CVE-2026-33843 | Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | 9.1 | 0.47% | 2026-05-22 | 2026-06-17 |
| CVE-2026-33117 | The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6. | 9.1 | 0.48% | 2026-05-12 | 2026-06-17 |
| CVE-2026-47280 | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. | 10.0 | 0.49% | 2026-05-22 | 2026-06-17 |
| CVE-2026-42822 | Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. | 10.0 | 0.49% | 2026-05-18 | 2026-06-17 |
| CVE-2026-24305 | Azure Entra ID Elevation of Privilege Vulnerability | 9.3 | 0.50% | 2026-01-22 | 2026-06-17 |
| CVE-2026-48584 | Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. | 9.9 | 0.50% | 2026-06-19 | 2026-06-29 |
| CVE-2026-35431 | Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. | 10.0 | 0.51% | 2026-04-23 | 2026-06-17 |