Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.6Vendor: CriticalMS Server

High [CVE-2026-69519] Azure Stack HCI Information Disclosure Vulnerability

Azure Stack HCI Information Disclosure Vulnerability

CVE-2026-69519
Unclassified
Aug 20, 2026
Critical9.6MS Server

Critical [CVE-2026-48582] Microsoft Exchange Online Elevation of Privilege Vulnerability

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

CVE-2026-48582
Exchange Server
Jun 19, 2026
Critical10.0MS Server

Critical [CVE-2026-45480] Azure Active Directory Elevation of Privilege Vulnerability

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-45480
Windows Server
Jun 19, 2026
Critical9.1MS Server

Critical [CVE-2026-48579] Microsoft Exchange Online Information Disclosure Vulnerability

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

CVE-2026-48579
Exchange Server
Jun 4, 2026
High7.7MS Server

High [CVE-2026-26147] Azure Stack HCI Information Disclosure Vulnerability

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. Affected product named by the advisory: Azure Stack HCI.

CVE-2026-26147
Unclassified
May 22, 2026
High7.8MS Server

High [CVE-2025-27743] Microsoft System Center Elevation of Privilege Vulnerability

Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: System Center Data Protection Manager 2019; System Center Data Protection Manager 2022; System Center Data Protection Manager 2025; System Center Operations Manager 2019; and 11 more. Affected products named by the advisory: System Center Operations Manager 2022; System Center Operations Manager 2025; System Center Orchestrator 2019; System Center Orchestrator 2022; and 7 more.

CVE-2025-27743
Unclassified
Apr 8, 2025
High8.1MS Server

High [CVE-2022-37966] Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability

Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2008 Service Pack 2; Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2 (Server Core installation); and 9 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 1 more.

CVE-2022-37966
Windows Server
Nov 9, 2022
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2020-0787] elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1909 (Server Core installation); Windows Server, version 1903 (Server Core installation).

CVE-2020-0787
Windows Server
Mar 12, 2020
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2020-0618] remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU); Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR); Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR); and 1 more. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU).

CVE-2020-0618
SQL Server
Feb 11, 2020
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1458] elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. Affected product named by the advisory: Windows Server.

CVE-2019-1458
Windows Server
Dec 10, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1405] elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).

CVE-2019-1405
Windows Server
Nov 12, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1129 +1] Windows Server: elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).

CVE-2019-1129CVE-2019-1130
Windows Server
Jul 29, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1068] Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR): remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR); Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR); Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR); Microsoft SQL Server 2017 for x64-based Systems (GDR); and 5 more. Affected products named by the advisory: Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU); Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR); and 1 more.

CVE-2019-1068
SQL Server
Jul 15, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2018-8453] elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2018-8453
Windows Server
Oct 10, 2018
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2018-8174] remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2018-8174
Windows Server
May 9, 2018
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2018-8120 +3] elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.

CVE-2018-8120CVE-2018-8124CVE-2018-8164+1
Windows Server
May 9, 2018