Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-56178 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-56176 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-56175 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-56173 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-56168 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. | ||
| CVE-2026-56159 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-56157 | Med | 0.00 | 5.4 | 0.01 | Jul 14, 2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-56156 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55949 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55947 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55944 | Cri | 0.00 | 9.8 | 0.02 | Jul 14, 2026 | Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-55898 | Med | 0.00 | 6.1 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55145 | Med | 0.00 | 6.3 | 0.01 | Jul 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network. | ||
| CVE-2026-55142 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55141 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55140 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55139 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55138 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55137 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55136 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55135 | Med | 0.00 | 4.6 | 0.01 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-55134 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55133 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55132 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55131 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55130 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55129 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55128 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55127 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55126 | Hig | 0.00 | 7.3 | 0.01 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-55125 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55124 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55123 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55122 | Hig | 0.00 | 7.1 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55121 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55120 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55058 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55057 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55056 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55055 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55054 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-55053 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55052 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-55051 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-55050 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55049 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55048 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55047 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55046 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55045 | Hig | 0.00 | 8.4 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. |
- risk 0.00cvss 5.5epss 0.00
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.0epss 0.00
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.5epss 0.01
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
- risk 0.00cvss 9.8epss 0.01
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 5.4epss 0.01
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 9.8epss 0.02
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 6.1epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 6.3epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.
- risk 0.00cvss 5.5epss 0.01
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.01
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 4.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 7.8epss 0.01
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.01
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.01
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.01
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.01
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 7.8epss 0.01
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 5.5epss 0.01
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.1epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 5.5epss 0.01
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.01
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 6.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 8.8epss 0.01
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 6.5epss 0.01
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
- risk 0.00cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 8.4epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Page 291 of 314