Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45496 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2026-44806 | Med | 0.00 | 5.3 | 0.01 | Jul 14, 2026 | Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-44800 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-42990 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42982 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-42975 | Hig | 0.00 | 8.0 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-42900 | Hig | 0.00 | 8.1 | 0.01 | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-41087 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-40422 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-40400 | Hig | 0.00 | 8.0 | 0.01 | Jul 14, 2026 | Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. | ||
| CVE-2026-40378 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-34349 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. | ||
| CVE-2026-34348 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-34346 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. | ||
| CVE-2026-34328 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. | ||
| CVE-2026-33842 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-58596 | Hig | 0.00 | 8.3 | 0.01 | Jul 12, 2026 | Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-58281 | Hig | 0.00 | 8.3 | 0.01 | Jul 11, 2026 | Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-57476 | Med | 0.00 | 4.8 | 0.00 | Jul 10, 2026 | Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network… | ||
| CVE-2026-57475 | Med | 0.00 | 5.3 | 0.01 | Jul 10, 2026 | Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI Assist for Customer restricted… | ||
| CVE-2026-57474 | Med | 0.00 | 5.3 | 0.01 | Jul 10, 2026 | Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist for Customer restricted network… | ||
| CVE-2026-47646 | Cri | 0.00 | 9.3 | 0.00 | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-58525 | Hig | 0.00 | 8.2 | 0.00 | Jul 8, 2026 | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-58523 | Med | 0.00 | 6.5 | 0.01 | Jul 3, 2026 | Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-58597 | Med | 0.00 | 4.3 | 0.01 | Jul 3, 2026 | Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-58524 | Med | 0.00 | 5.4 | 0.00 | Jul 3, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-58522 | Med | 0.00 | 6.8 | 0.00 | Jul 3, 2026 | Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-58300 | Med | 0.00 | 6.2 | 0.00 | Jul 3, 2026 | Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-58299 | Hig | 0.00 | 7.5 | 0.00 | Jul 3, 2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-58298 | Hig | 0.00 | 7.2 | 0.00 | Jul 3, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-58297 | Hig | 0.00 | 7.1 | 0.01 | Jul 3, 2026 | Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-58296 | Hig | 0.00 | 7.1 | 0.01 | Jul 3, 2026 | Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-58295 | Hig | 0.00 | 8.3 | 0.01 | Jul 3, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-58294 | Hig | 0.00 | 7.5 | 0.01 | Jul 3, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-58293 | Hig | 0.00 | 8.1 | 0.01 | Jul 3, 2026 | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-58292 | Hig | 0.00 | 7.5 | 0.00 | Jul 3, 2026 | Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-58291 | Med | 0.00 | 6.1 | 0.01 | Jul 3, 2026 | Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-58290 | Hig | 0.00 | 7.5 | 0.00 | Jul 3, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-58289 | Cri | 0.00 | 9.0 | 0.02 | Jul 3, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-58288 | Hig | 0.00 | 8.3 | 0.01 | Jul 3, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-58287 | Hig | 0.00 | 8.3 | 0.01 | Jul 3, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-58286 | Hig | 0.00 | 8.1 | 0.00 | Jul 3, 2026 | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-58285 | Hig | 0.00 | 8.3 | 0.01 | Jul 3, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-58284 | Hig | 0.00 | 8.3 | 0.01 | Jul 3, 2026 | Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-58283 | Hig | 0.00 | 8.1 | 0.00 | Jul 3, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-58282 | Hig | 0.00 | 8.1 | 0.00 | Jul 3, 2026 | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-58278 | Med | 0.00 | 5.4 | 0.00 | Jul 3, 2026 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-58276 | Hig | 0.00 | 7.5 | 0.01 | Jul 3, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-57993 | Hig | 0.00 | 7.4 | 0.01 | Jul 3, 2026 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-57992 | Hig | 0.00 | 7.5 | 0.01 | Jul 3, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
- risk 0.00cvss 5.5epss 0.00
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
- risk 0.00cvss 5.3epss 0.01
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 7.8epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 9.8epss 0.01
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 7.8epss 0.00
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.0epss 0.01
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.00cvss 8.1epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.00cvss 8.0epss 0.01
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
- risk 0.00cvss 7.5epss 0.01
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
- risk 0.00cvss 6.5epss 0.01
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.
- risk 0.00cvss 5.5epss 0.00
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.00cvss 8.3epss 0.01
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
- risk 0.00cvss 8.3epss 0.01
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 4.8epss 0.00
Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network…
- risk 0.00cvss 5.3epss 0.01
Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI Assist for Customer restricted…
- risk 0.00cvss 5.3epss 0.01
Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist for Customer restricted network…
- risk 0.00cvss 9.3epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
- risk 0.00cvss 8.2epss 0.00
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.00cvss 6.5epss 0.01
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.00cvss 4.3epss 0.01
Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.00cvss 5.4epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.00cvss 6.8epss 0.00
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 6.2epss 0.00
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.5epss 0.00
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 7.2epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.00cvss 7.1epss 0.01
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
- risk 0.00cvss 7.1epss 0.01
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
- risk 0.00cvss 8.3epss 0.01
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.00cvss 7.5epss 0.01
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.1epss 0.01
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 7.5epss 0.00
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 6.1epss 0.01
Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- risk 0.00cvss 7.5epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 9.0epss 0.02
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.3epss 0.01
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.3epss 0.01
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.1epss 0.00
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.00cvss 8.3epss 0.01
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.3epss 0.01
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.1epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.00cvss 8.1epss 0.00
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.00cvss 5.4epss 0.00
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.00cvss 7.5epss 0.01
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 7.4epss 0.01
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.00cvss 7.5epss 0.01
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Page 300 of 314