Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-0183 | Hig | 0.58 | 8.8 | 0.16 | May 11, 2016 | The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Microsoft Office Graphics RCE… | ||
| CVE-2016-0147 | Hig | 0.58 | 8.8 | 0.16 | Apr 12, 2016 | Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability." | ||
| CVE-2016-0068 | Hig | 0.58 | 8.8 | 0.15 | Feb 18, 2016 | Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0069. | ||
| CVE-2016-0071 | Hig | 0.58 | 8.8 | 0.14 | Feb 10, 2016 | Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | ||
| CVE-2016-0067 | Hig | 0.58 | 8.8 | 0.14 | Feb 10, 2016 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060,… | ||
| CVE-2016-0064 | Hig | 0.58 | 8.8 | 0.14 | Feb 10, 2016 | Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | ||
| CVE-2016-0015 | Hig | 0.58 | 7.8 | 0.49 | Jan 13, 2016 | DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "DirectShow Heap… | ||
| CVE-2016-0009 | Hig | 0.58 | 8.8 | 0.15 | Jan 13, 2016 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitrary code via unspecified vectors, aka "Win32k Remote Code Execution Vulnerability." | ||
| CVE-2011-1265 | Hig | 0.58 | 8.8 | 0.06 | Jul 13, 2011 | The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth… | ||
| CVE-2010-0820 | Hig | 0.58 | 8.8 | 0.14 | Sep 15, 2010 | Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2; Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server… | ||
| CVE-2007-4040 | Hig | 0.58 | 8.8 | 0.13 | Jul 27, 2007 | Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are… | ||
| CVE-2026-24301 | Hig | 0.57 | 8.8 | 0.02 | Aug 18, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-73298 | Hig | 0.57 | — | 0.01 | Aug 12, 2026 | The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and earlier, a security vulnerability was… | ||
| CVE-2026-70337 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-70336 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-70329 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-70326 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-70324 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-70321 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-69320 | Hig | 0.57 | 8.8 | 0.00 | Aug 11, 2026 | Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-66808 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-66805 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65815 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65811 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65807 | Hig | 0.57 | 8.8 | 0.00 | Aug 11, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65768 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65767 | Hig | 0.57 | 8.8 | 0.00 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-65665 | Hig | 0.57 | 8.8 | 0.03 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65663 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65660 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-65658 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-64921 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-64901 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-63514 | Hig | 0.57 | 8.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-62913 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-62872 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-62869 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-62827 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-62824 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62823 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-62822 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62818 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-62817 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-62816 | Hig | 0.57 | 8.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-62800 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-62795 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62790 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-62785 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62784 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-59133 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. |
- risk 0.58cvss 8.8epss 0.16
The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Microsoft Office Graphics RCE…
- risk 0.58cvss 8.8epss 0.16
Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability."
- risk 0.58cvss 8.8epss 0.15
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0069.
- risk 0.58cvss 8.8epss 0.14
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
- risk 0.58cvss 8.8epss 0.14
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060,…
- risk 0.58cvss 8.8epss 0.14
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
- risk 0.58cvss 7.8epss 0.49
DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "DirectShow Heap…
- risk 0.58cvss 8.8epss 0.15
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitrary code via unspecified vectors, aka "Win32k Remote Code Execution Vulnerability."
- risk 0.58cvss 8.8epss 0.06
The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth…
- risk 0.58cvss 8.8epss 0.14
Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2; Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server…
- risk 0.58cvss 8.8epss 0.13
Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are…
- risk 0.57cvss 8.8epss 0.02
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.57cvss —epss 0.01
The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and earlier, a security vulnerability was…
- risk 0.57cvss 8.8epss 0.01
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.00
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
- risk 0.57cvss 8.8epss 0.03
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
- risk 0.57cvss 8.8epss 0.01
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.57cvss 8.8epss 0.01
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.57cvss 8.8epss 0.00
Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
Page 25 of 314