Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-25181 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2026 | Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-23674 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2026 | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-23664 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2026 | Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-23662 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2026 | Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-23661 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2026 | Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-58107 | Hig | 0.49 | 7.5 | 0.00 | Mar 2, 2026 | In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password. | ||
| CVE-2026-21511 | Hig | 0.49 | 7.5 | 0.04 | Feb 10, 2026 | Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-21260 | Hig | 0.49 | 7.5 | 0.01 | Feb 10, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-21243 | Hig | 0.49 | 7.5 | 0.01 | Feb 10, 2026 | Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-20846 | Hig | 0.49 | 7.5 | 0.01 | Feb 10, 2026 | Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-21520 | Hig | 0.49 | 7.5 | 0.01 | Jan 22, 2026 | Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector | ||
| CVE-2026-21226 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. | ||
| CVE-2026-20965 | Hig | 0.49 | 7.5 | 0.00 | Jan 13, 2026 | Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20934 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-20929 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-20926 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-20921 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-20919 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-20875 | Hig | 0.49 | 7.5 | 0.02 | Jan 13, 2026 | Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-20854 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-20849 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-20848 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-0386 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2026 | Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2025-64666 | Hig | 0.49 | 7.5 | 0.01 | Dec 9, 2025 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-64658 | Hig | 0.49 | 7.5 | 0.00 | Dec 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-60704 | Hig | 0.49 | 7.5 | 0.01 | Nov 11, 2025 | Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-59502 | Hig | 0.49 | 7.5 | 0.01 | Oct 14, 2025 | Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-59248 | Hig | 0.49 | 7.5 | 0.01 | Oct 14, 2025 | Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-58726 | Hig | 0.49 | 7.5 | 0.01 | Oct 14, 2025 | Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-55326 | Hig | 0.49 | 7.5 | 0.01 | Oct 14, 2025 | Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-59251 | Hig | 0.49 | 7.6 | 0.01 | Sep 24, 2025 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2025-55243 | Hig | 0.49 | 7.5 | 0.01 | Sep 9, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-54919 | Hig | 0.49 | 7.5 | 0.00 | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | ||
| CVE-2025-53805 | Hig | 0.49 | 7.5 | 0.01 | Sep 9, 2025 | Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-36853 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2025 | A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of… | ||
| CVE-2025-55238 | Hig | 0.49 | 7.5 | 0.01 | Sep 4, 2025 | Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability | ||
| CVE-2025-55231 | Hig | 0.49 | 7.5 | 0.00 | Aug 21, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-53793 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2025 | Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-53783 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2025 | Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-50169 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-33051 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-49744 | Hig | 0.49 | 7.0 | 0.01 | Jul 8, 2025 | Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49718 | Hig | 0.49 | 7.5 | 0.03 | Jul 8, 2025 | Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-49716 | Hig | 0.49 | 7.5 | 0.01 | Jul 8, 2025 | Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-49677 | Hig | 0.49 | 7.0 | 0.01 | Jul 8, 2025 | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-48814 | Hig | 0.49 | 7.5 | 0.01 | Jul 8, 2025 | Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-47988 | Hig | 0.49 | 7.5 | 0.01 | Jul 8, 2025 | Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2025-49715 | Hig | 0.49 | 7.5 | 0.01 | Jun 20, 2025 | Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-30399 | Hig | 0.49 | 7.5 | 0.01 | Jun 13, 2025 | Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-33068 | Hig | 0.49 | 7.5 | 0.02 | Jun 10, 2025 | Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. |
- risk 0.49cvss 7.5epss 0.01
Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.01
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.49cvss 7.5epss 0.01
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.01
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.01
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.00
In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.
- risk 0.49cvss 7.5epss 0.04
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
- risk 0.49cvss 7.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
- risk 0.49cvss 7.5epss 0.01
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector
- risk 0.49cvss 7.5epss 0.01
Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.
- risk 0.49cvss 7.5epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.02
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.49cvss 7.5epss 0.01
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
- risk 0.49cvss 7.5epss 0.01
Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.49cvss 7.5epss 0.01
Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.6epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network.
- risk 0.49cvss 7.5epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
- risk 0.49cvss 7.5epss 0.01
Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of…
- risk 0.49cvss 7.5epss 0.01
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.01
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.0epss 0.01
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- risk 0.49cvss 7.5epss 0.03
Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.01
Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.0epss 0.01
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- risk 0.49cvss 7.5epss 0.01
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.49cvss 7.5epss 0.01
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.49cvss 7.5epss 0.01
Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.01
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.02
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
Page 121 of 314