Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65785 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. | ||
| CVE-2026-65769 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-63516 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-63512 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. | ||
| CVE-2026-62915 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | ||
| CVE-2026-62912 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. | ||
| CVE-2026-62901 | Hig | 0.42 | 7.5 | 0.01 | Aug 11, 2026 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-62898 | Hig | 0.42 | 7.5 | 0.01 | Aug 11, 2026 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-62839 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-62837 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-62814 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62782 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-62750 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. | ||
| CVE-2026-62745 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62742 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62720 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62718 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62716 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62715 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62714 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2026-62708 | Med | 0.42 | 6.4 | 0.00 | Aug 11, 2026 | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. | ||
| CVE-2026-61924 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-61921 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-61918 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-61345 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | ||
| CVE-2026-59138 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | ||
| CVE-2026-58639 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-47285 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-40375 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-66326 | Med | 0.42 | 6.5 | 0.00 | Aug 4, 2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-66314 | Med | 0.42 | 6.5 | 0.00 | Aug 4, 2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-66312 | Med | 0.42 | 6.5 | 0.01 | Aug 4, 2026 | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-53598 | Hig | 0.42 | 7.5 | 0.01 | Jul 16, 2026 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowed roots, allowing an attacker-controlled… | ||
| CVE-2026-59862 | Hig | 0.42 | 7.5 | 0.01 | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation.DescriptionTemplate and… | ||
| CVE-2026-59861 | Hig | 0.42 | 7.5 | 0.02 | Jul 16, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs… | ||
| CVE-2026-50659 | Med | 0.42 | 6.5 | 0.01 | Jul 14, 2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-50519 | Med | 0.42 | 6.5 | 0.01 | Jun 19, 2026 | Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-42895 | Med | 0.42 | 6.5 | 0.01 | Jun 19, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | ||
| CVE-2026-50508 | Med | 0.42 | 6.5 | 0.09 | Jun 9, 2026 | Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-47287 | Med | 0.42 | 6.5 | 0.01 | Jun 9, 2026 | Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. | ||
| CVE-2026-47284 | Med | 0.42 | 6.5 | 0.01 | Jun 9, 2026 | Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-45591 | Hig | 0.42 | 7.5 | 0.02 | Jun 9, 2026 | Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-45501 | Med | 0.42 | 6.5 | 0.00 | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-45454 | Med | 0.42 | 6.5 | 0.02 | Jun 9, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-42907 | Med | 0.42 | 6.5 | 0.01 | Jun 9, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. | ||
| CVE-2026-42903 | Med | 0.42 | 6.5 | 0.01 | Jun 9, 2026 | Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. | ||
| CVE-2026-47655 | Med | 0.42 | 6.5 | 0.01 | Jun 4, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-47644 | Med | 0.42 | 6.5 | 0.01 | Jun 4, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-42824 | Med | 0.42 | 6.5 | 0.08 | Jun 4, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-42827 | Med | 0.42 | 6.5 | 0.01 | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
- risk 0.42cvss 6.5epss 0.00
Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
- risk 0.42cvss 6.5epss 0.00
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
- risk 0.42cvss 6.5epss 0.01
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
- risk 0.42cvss 7.5epss 0.01
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
- risk 0.42cvss 7.5epss 0.01
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.5epss 0.00
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.42cvss 6.4epss 0.00
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.00
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.42cvss 6.5epss 0.00
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
- risk 0.42cvss 7.5epss 0.01
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowed roots, allowing an attacker-controlled…
- risk 0.42cvss 7.5epss 0.01
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation.DescriptionTemplate and…
- risk 0.42cvss 7.5epss 0.02
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs…
- risk 0.42cvss 6.5epss 0.01
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
- risk 0.42cvss 6.5epss 0.09
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 7.5epss 0.02
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.02
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
- risk 0.42cvss 6.5epss 0.01
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.08
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Page 165 of 314