Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69306 | Hig | 0.53 | 8.2 | 0.00 | Aug 11, 2026 | Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-66802 | Hig | 0.53 | 8.1 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65796 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65789 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65679 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-63520 | Hig | 0.53 | 8.1 | 0.03 | Aug 11, 2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62889 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62820 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62819 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | ||
| CVE-2026-62792 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62781 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62778 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-66318 | Hig | 0.53 | 8.1 | 0.00 | Aug 4, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-50528 | Hig | 0.53 | 8.2 | 0.01 | Jul 14, 2026 | Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-47304 | Hig | 0.53 | 8.1 | 0.00 | Jul 14, 2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-47652 | Hig | 0.53 | 8.2 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-47631 | Hig | 0.53 | 8.1 | 0.00 | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-45635 | Hig | 0.53 | 8.1 | 0.01 | Jun 9, 2026 | Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-45599 | Hig | 0.53 | 8.1 | 0.01 | Jun 9, 2026 | Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-45503 | Hig | 0.53 | 8.1 | 0.00 | Jun 9, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-45476 | Hig | 0.53 | 8.2 | 0.00 | Jun 9, 2026 | Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-44822 | Hig | 0.53 | 8.2 | 0.01 | Jun 9, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-42987 | Hig | 0.53 | 8.1 | 0.01 | Jun 9, 2026 | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42981 | Hig | 0.53 | 8.1 | 0.01 | Jun 9, 2026 | Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42974 | Hig | 0.53 | 8.1 | 0.01 | Jun 9, 2026 | Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42835 | Hig | 0.53 | 8.1 | 0.01 | Jun 9, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-46402 | Hig | 0.53 | 8.1 | 0.01 | May 27, 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client can supply path traversal sequences in… | ||
| CVE-2026-45584 | Hig | 0.53 | 8.1 | 0.01 | May 20, 2026 | Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-40415 | Hig | 0.53 | 8.1 | 0.01 | May 12, 2026 | Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-33833 | Hig | 0.53 | 8.2 | 0.01 | May 12, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-41105 | Hig | 0.53 | 8.1 | 0.01 | May 7, 2026 | Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-34327 | Hig | 0.53 | 8.2 | 0.01 | May 7, 2026 | Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-33827 | Hig | 0.53 | 8.1 | 0.01 | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-26148 | Hig | 0.53 | 8.1 | 0.00 | Mar 10, 2026 | External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-26105 | Hig | 0.53 | 8.1 | 0.01 | Mar 10, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-21535 | Hig | 0.53 | 8.2 | 0.01 | Feb 19, 2026 | Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-21525 | Med | 0.53 | 6.2 | 0.05 | KEV | Feb 10, 2026 | Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. | |
| CVE-2026-21228 | Hig | 0.53 | 8.1 | 0.01 | Feb 10, 2026 | Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-21532 | Hig | 0.53 | 8.2 | 0.01 | Feb 5, 2026 | Azure Function Information Disclosure Vulnerability | ||
| CVE-2026-21227 | Hig | 0.53 | 8.2 | 0.01 | Jan 22, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-20856 | Hig | 0.53 | 8.1 | 0.01 | Jan 13, 2026 | Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-64677 | Hig | 0.53 | 8.2 | 0.01 | Dec 18, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-30398 | Hig | 0.53 | 8.1 | 0.01 | Nov 11, 2025 | Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-59292 | Hig | 0.53 | 8.2 | 0.00 | Oct 14, 2025 | External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-59291 | Hig | 0.53 | 8.2 | 0.00 | Oct 14, 2025 | External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-36854 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2025 | A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution. Per CWE-416: Use… | ||
| CVE-2025-50177 | Hig | 0.53 | 8.1 | 0.04 | Aug 12, 2025 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-53787 | Hig | 0.53 | 8.2 | 0.01 | Aug 7, 2025 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | ||
| CVE-2025-53786 | Hig | 0.53 | 8.0 | 0.07 | Aug 6, 2025 | On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation,… | ||
| CVE-2025-53771 | Med | 0.53 | 6.5 | 1.00 | Jul 20, 2025 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
- risk 0.53cvss 8.2epss 0.00
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.53cvss 8.1epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.03
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
- risk 0.53cvss 8.1epss 0.01
Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.00
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- risk 0.53cvss 8.2epss 0.01
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.53cvss 8.1epss 0.00
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.53cvss 8.2epss 0.00
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
- risk 0.53cvss 8.1epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.00
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
- risk 0.53cvss 8.2epss 0.00
Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
- risk 0.53cvss 8.2epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
- risk 0.53cvss 8.1epss 0.01
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client can supply path traversal sequences in…
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.2epss 0.01
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 8.1epss 0.01
Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.2epss 0.01
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 8.1epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.00
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.
- risk 0.53cvss 8.1epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 8.2epss 0.01
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
- risk 0.53cvss 6.2epss 0.05
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
- risk 0.53cvss 8.1epss 0.01
Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.2epss 0.01
Azure Function Information Disclosure Vulnerability
- risk 0.53cvss 8.2epss 0.01
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.01
Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.2epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 8.1epss 0.01
Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.
- risk 0.53cvss 8.2epss 0.00
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
- risk 0.53cvss 8.2epss 0.00
External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
- risk 0.53cvss 8.1epss 0.01
A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution. Per CWE-416: Use…
- risk 0.53cvss 8.1epss 0.04
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.2epss 0.01
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
- risk 0.53cvss 8.0epss 0.07
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation,…
- risk 0.53cvss 6.5epss 1.00
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Page 48 of 314