Microsoft vulnerabilities
Showing 1 - 50 of 2.6K CVEs
- CVE-2026-72984 Published Aug 28, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-70331 Published Aug 28, 2026
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-70309 Published Aug 28, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-66798 Published Aug 28, 2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-66324 Published Aug 28, 2026
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-66323 Published Aug 28, 2026
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-62904 Published Aug 28, 2026
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- CVE-2026-58616 Published Aug 28, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.
- CVE-2026-70105 Published Aug 20, 2026
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
- CVE-2026-72970 Published Aug 14, 2026
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-70339 Published Aug 11, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-70355 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-70354 Published Aug 11, 2026
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
- CVE-2026-70326 Published Aug 11, 2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-70324 Published Aug 11, 2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-70321 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-70306 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-66808 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-66805 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65813 Published Aug 11, 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-65810 Published Aug 11, 2026
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-65769 Published Aug 11, 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
- CVE-2026-65768 Published Aug 11, 2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
- CVE-2026-65767 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
- CVE-2026-65665 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65663 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65660 Published Aug 11, 2026
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65658 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-64922 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-64921 Published Aug 11, 2026
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-64916 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-64902 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-64901 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-64900 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-64897 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-63520 Published Aug 11, 2026
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-63516 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-63514 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-63512 Published Aug 11, 2026
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
- CVE-2026-62917 Published Aug 11, 2026
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-62915 Published Aug 11, 2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
- CVE-2026-62914 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
- CVE-2026-62913 Published Aug 11, 2026
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
- CVE-2026-62912 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
- CVE-2026-62911 Published Aug 11, 2026
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-62910 Published Aug 11, 2026
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-62897 Published Aug 11, 2026
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
- CVE-2026-62872 Published Aug 11, 2026
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
- CVE-2026-62839 Published Aug 11, 2026
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-62837 Published Aug 11, 2026
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high 8.8
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
medium 5.4
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
medium 4.3
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium 6.5
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
medium 5.4
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
medium 5.4
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.
medium 4.4
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
medium 6.5
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high 8.3
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
medium 5.4
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
high 7.3
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
high 7.8
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
high 8.8
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
high 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
critical 9.3
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
medium 6.5
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
high 7.8
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
medium 6.5
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
high 8.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
high 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
high 8.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
high 7.3
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
high 8.1
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 6.5
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
medium 6.5
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
medium 6.5
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
high 7.3
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
high 8.8
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
medium 6.5
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
high 8.0
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
high 7.2
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
high 7.0
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
high 8.8
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 6.5
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
medium 6.5