Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45650 | Med | 0.28 | 4.3 | 0.01 | Jun 9, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-40421 | Med | 0.28 | 4.3 | 0.01 | May 12, 2026 | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-40416 | Med | 0.28 | 4.3 | 0.00 | May 12, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-35429 | Med | 0.28 | 4.3 | 0.01 | May 12, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-32175 | Med | 0.28 | 4.3 | 0.01 | May 12, 2026 | A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited… | ||
| CVE-2026-33118 | Med | 0.28 | 4.3 | 0.01 | Apr 10, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-20936 | Med | 0.28 | 4.3 | 0.00 | Jan 13, 2026 | Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. | ||
| CVE-2025-62223 | Med | 0.28 | 4.3 | 0.00 | Dec 5, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-60728 | Med | 0.28 | 4.3 | 0.01 | Nov 11, 2025 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-62931 | Med | 0.28 | 4.3 | 0.00 | Oct 27, 2025 | Missing Authorization vulnerability in microsoftstart MSN Partner Hub microsoft-start allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MSN Partner Hub: from n/a through <= 2.9. | ||
| CVE-2025-54917 | Med | 0.28 | 4.3 | 0.01 | Sep 9, 2025 | Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-54107 | Med | 0.28 | 4.3 | 0.01 | Sep 9, 2025 | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-49755 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-49736 | Med | 0.28 | 4.3 | 0.00 | Aug 12, 2025 | The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-25001 | Med | 0.28 | 4.3 | 0.01 | Apr 4, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-24055 | Med | 0.28 | 4.3 | 0.01 | Mar 11, 2025 | Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack. | ||
| CVE-2025-21247 | Med | 0.28 | 4.3 | 0.03 | Mar 11, 2025 | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-21404 | Med | 0.28 | 4.3 | 0.01 | Feb 6, 2025 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2025-21332 | Med | 0.28 | 4.3 | 0.01 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21329 | Med | 0.28 | 4.3 | 0.02 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21328 | Med | 0.28 | 4.3 | 0.02 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21269 | Med | 0.28 | 4.3 | 0.05 | Jan 14, 2025 | Windows HTML Platforms Security Feature Bypass Vulnerability | ||
| CVE-2025-21268 | Med | 0.28 | 4.3 | 0.02 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21219 | Med | 0.28 | 4.3 | 0.03 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21189 | Med | 0.28 | 4.3 | 0.03 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2024-49103 | Med | 0.28 | 4.3 | 0.01 | Dec 12, 2024 | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | ||
| CVE-2024-49099 | Med | 0.28 | 4.3 | 0.01 | Dec 12, 2024 | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | ||
| CVE-2024-49098 | Med | 0.28 | 4.3 | 0.01 | Dec 12, 2024 | Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | ||
| CVE-2024-49041 | Med | 0.28 | 4.3 | 0.01 | Dec 6, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-49054 | Med | 0.28 | 4.3 | 0.01 | Nov 22, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-43577 | Med | 0.28 | 4.3 | 0.00 | Oct 18, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-38221 | Med | 0.28 | 4.3 | 0.00 | Sep 19, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-38093 | Med | 0.28 | 4.3 | 0.00 | Jun 20, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-38083 | Med | 0.28 | 4.3 | 0.00 | Jun 13, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-29056 | Med | 0.28 | 4.3 | 0.01 | Apr 9, 2024 | Windows Authentication Elevation of Privilege Vulnerability | ||
| CVE-2024-29981 | Med | 0.28 | 4.3 | 0.01 | Apr 4, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-29057 | Med | 0.28 | 4.3 | 0.01 | Mar 22, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-26196 | Med | 0.28 | 4.3 | 0.01 | Mar 21, 2024 | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | ||
| CVE-2024-26167 | Med | 0.28 | 4.3 | 0.01 | Mar 7, 2024 | Microsoft Edge for Android Spoofing Vulnerability | ||
| CVE-2024-26188 | Med | 0.28 | 4.3 | 0.01 | Feb 23, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-21382 | Med | 0.28 | 4.3 | 0.01 | Jan 26, 2024 | Microsoft Edge for Android Information Disclosure Vulnerability | ||
| CVE-2023-36878 | Med | 0.28 | 4.3 | 0.01 | Dec 15, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2023-38174 | Med | 0.28 | 4.3 | 0.02 | Dec 7, 2023 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | ||
| CVE-2023-36026 | Med | 0.28 | 4.3 | 0.01 | Nov 16, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2023-36029 | Med | 0.28 | 4.3 | 0.01 | Nov 3, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2023-36767 | Med | 0.28 | 4.3 | 0.03 | Sep 12, 2023 | Microsoft Office Security Feature Bypass Vulnerability | ||
| CVE-2023-38173 | Med | 0.28 | 4.3 | 0.01 | Jul 21, 2023 | Microsoft Edge for Android Spoofing Vulnerability | ||
| CVE-2023-36883 | Med | 0.28 | 4.3 | 0.01 | Jul 14, 2023 | Microsoft Edge for iOS Spoofing Vulnerability | ||
| CVE-2023-33165 | Med | 0.28 | 4.3 | 0.01 | Jul 11, 2023 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | ||
| CVE-2021-42307 | Med | 0.28 | 4.3 | 0.01 | Jul 1, 2023 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
- risk 0.28cvss 4.3epss 0.01
User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.
- risk 0.28cvss 4.3epss 0.01
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.28cvss 4.3epss 0.00
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.28cvss 4.3epss 0.01
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.28cvss 4.3epss 0.01
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited…
- risk 0.28cvss 4.3epss 0.01
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.28cvss 4.3epss 0.00
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
- risk 0.28cvss 4.3epss 0.00
User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
- risk 0.28cvss 4.3epss 0.01
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- risk 0.28cvss 4.3epss 0.00
Missing Authorization vulnerability in microsoftstart MSN Partner Hub microsoft-start allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MSN Partner Hub: from n/a through <= 2.9.
- risk 0.28cvss 4.3epss 0.01
Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.28cvss 4.3epss 0.01
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.28cvss 4.3epss 0.00
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
- risk 0.28cvss 4.3epss 0.00
The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
- risk 0.28cvss 4.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.28cvss 4.3epss 0.01
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.
- risk 0.28cvss 4.3epss 0.03
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.05
Windows HTML Platforms Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.03
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.03
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.01
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Windows Authentication Elevation of Privilege Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge for Android Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge for Android Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.03
Microsoft Office Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge for Android Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge for iOS Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft SharePoint Server Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Page 214 of 314