Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.
Assigner (CNA / source):[email protected] Remove this filter
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2026-48584 | Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. | 9.9 | N/A | 2026-06-19 | 2026-06-19 |
| CVE-2026-48582 | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 9.6 | N/A | 2026-06-19 | 2026-06-19 |
| CVE-2026-47645 | Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. | 8.8 | N/A | 2026-06-19 | 2026-06-19 |
| CVE-2026-45480 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | 10.0 | N/A | 2026-06-19 | 2026-06-19 |
| CVE-2026-32208 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network. | 8.8 | N/A | 2026-06-19 | 2026-06-19 |
| CVE-2026-54130 | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 9.8 | N/A | 2026-06-18 | 2026-06-18 |
| CVE-2026-47647 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. | 9.9 | N/A | 2026-06-18 | 2026-06-18 |
| CVE-2026-47633 | Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. | 7.5 | N/A | 2026-06-18 | 2026-06-18 |
| CVE-2026-32174 | Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. | 7.7 | N/A | 2026-06-18 | 2026-06-18 |
| CVE-2026-50656 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available. | 7.8 | 0.34% | 2026-06-16 | 2026-06-17 |
| CVE-2026-50512 | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 7.8 | 0.21% | 2026-06-09 | 2026-06-17 |
| CVE-2026-50511 | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 7.8 | 0.28% | 2026-06-09 | 2026-06-17 |
| CVE-2026-49161 | Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. | 7.8 | 0.19% | 2026-06-09 | 2026-06-17 |
| CVE-2026-49160 | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. | 7.5 | 0.97% | 2026-06-09 | 2026-06-17 |
| CVE-2026-48583 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 7.8 | 0.21% | 2026-06-09 | 2026-06-17 |
| CVE-2026-48578 | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 7.9 | 0.22% | 2026-06-09 | 2026-06-17 |
| CVE-2026-48576 | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 7.9 | 0.83% | 2026-06-09 | 2026-06-17 |
| CVE-2026-48575 | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 7.9 | 0.24% | 2026-06-09 | 2026-06-17 |
| CVE-2026-48574 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | 7.8 | 0.36% | 2026-06-09 | 2026-06-17 |
| CVE-2026-48573 | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 7.9 | 0.83% | 2026-06-09 | 2026-06-17 |