Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-0119 | Hig | 0.52 | 7.5 | 0.40 | Jun 1, 2004 | The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during… | ||
| CVE-2026-69414 | Hig | 0.51 | 7.8 | 0.01 | Aug 14, 2026 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide… | ||
| CVE-2026-50523 | Hig | 0.51 | 7.8 | 0.00 | Aug 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. | ||
| CVE-2026-70354 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-70347 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-70346 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-70345 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-70344 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-70338 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2026-70335 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-70313 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70311 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-69278 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2026-68817 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68816 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68815 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68814 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68812 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68811 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68810 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68807 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68806 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68805 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68804 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68803 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68801 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68800 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68798 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68796 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68795 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68794 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68793 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68792 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-66807 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-66804 | Hig | 0.51 | 7.8 | 0.05 | Aug 11, 2026 | Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-66799 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65814 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65810 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-65790 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65787 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65786 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65775 | Hig | 0.51 | 7.8 | 0.03 | Aug 11, 2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65774 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65773 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65673 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65672 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65671 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65664 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-65661 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-65657 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
- risk 0.52cvss 7.5epss 0.40
The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during…
- risk 0.51cvss 7.8epss 0.01
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide…
- risk 0.51cvss 7.8epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
- risk 0.51cvss 7.8epss 0.00
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.05
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.03
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Page 61 of 314