Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-26114 | Hig | 0.57 | 8.8 | 0.03 | Mar 10, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-26106 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-25188 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2026-25177 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-24283 | Hig | 0.57 | 8.8 | 0.00 | Mar 10, 2026 | Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-23669 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Use after free in RPC Runtime allows an authorized attacker to execute code over a network. | ||
| CVE-2026-23654 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-21262 | Hig | 0.57 | 8.8 | 0.02 | Mar 10, 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-20967 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-26119 | Hig | 0.57 | 8.8 | 0.01 | Feb 17, 2026 | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-21537 | Hig | 0.57 | 8.8 | 0.01 | Feb 10, 2026 | Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-21518 | Hig | 0.57 | 8.8 | 0.01 | Feb 10, 2026 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-21516 | Hig | 0.57 | 8.8 | 0.01 | Feb 10, 2026 | Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-21256 | Hig | 0.57 | 8.8 | 0.01 | Feb 10, 2026 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-21255 | Hig | 0.57 | 8.8 | 0.00 | Feb 10, 2026 | Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2025-61973 | Hig | 0.57 | 8.8 | 0.00 | Jan 15, 2026 | A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges. | ||
| CVE-2026-20868 | Hig | 0.57 | 8.8 | 0.01 | Jan 13, 2026 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-64678 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-64672 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2025-62550 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2025 | Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. | ||
| CVE-2025-62549 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2025 | Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-62456 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2025 | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. | ||
| CVE-2025-64655 | Hig | 0.57 | 8.8 | 0.00 | Nov 20, 2025 | Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-62222 | Hig | 0.57 | 8.8 | 0.01 | Nov 11, 2025 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-62220 | Hig | 0.57 | 8.8 | 0.01 | Nov 11, 2025 | Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-62211 | Hig | 0.57 | 8.7 | 0.01 | Nov 11, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2025-62210 | Hig | 0.57 | 8.7 | 0.01 | Nov 11, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2025-59499 | Hig | 0.57 | 8.8 | 0.01 | Nov 11, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-59295 | Hig | 0.57 | 8.8 | 0.02 | Oct 14, 2025 | Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-59249 | Hig | 0.57 | 8.8 | 0.01 | Oct 14, 2025 | Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-59237 | Hig | 0.57 | 8.8 | 0.02 | Oct 14, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2025-59228 | Hig | 0.57 | 8.8 | 0.01 | Oct 14, 2025 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2025-59213 | Hig | 0.57 | 8.8 | 0.00 | Oct 14, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2025-58718 | Hig | 0.57 | 8.8 | 0.01 | Oct 14, 2025 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-58716 | Hig | 0.57 | 8.8 | 0.00 | Oct 14, 2025 | Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-58715 | Hig | 0.57 | 8.8 | 0.00 | Oct 14, 2025 | Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59271 | Hig | 0.57 | 8.7 | 0.01 | Oct 9, 2025 | Redis Enterprise Elevation of Privilege Vulnerability | ||
| CVE-2025-59247 | Hig | 0.57 | 8.8 | 0.01 | Oct 9, 2025 | Azure PlayFab Elevation of Privilege Vulnerability | ||
| CVE-2025-55319 | Hig | 0.57 | 8.8 | 0.01 | Sep 12, 2025 | Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-55227 | Hig | 0.57 | 8.8 | 0.01 | Sep 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-54113 | Hig | 0.57 | 8.8 | 0.01 | Sep 9, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-54106 | Hig | 0.57 | 8.8 | 0.01 | Sep 9, 2025 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-36855 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2025 | A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access… | ||
| CVE-2025-53727 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-53143 | Hig | 0.57 | 8.8 | 0.06 | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | ||
| CVE-2025-53131 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2025 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-50163 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-49759 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-49758 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-49757 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
- risk 0.57cvss 8.8epss 0.03
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.
- risk 0.57cvss 8.8epss 0.01
Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.00
Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.8epss 0.01
Use after free in RPC Runtime allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.02
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.00
Improper access control in Windows Hyper-V allows an authorized attacker to bypass a security feature locally.
- risk 0.57cvss 8.8epss 0.00
A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.57cvss 8.8epss 0.01
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.00
Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.7epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
- risk 0.57cvss 8.7epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.02
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.00
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network.
- risk 0.57cvss 8.8epss 0.01
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.00
Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.8epss 0.00
Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
- risk 0.57cvss 8.7epss 0.01
Redis Enterprise Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.01
Azure PlayFab Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.01
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access…
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.06
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Page 27 of 314