Microsoft vulnerabilities

Showing 1 - 50 of 2.7K CVEs

  1. CVE-2026-69904 Published Sep 8, 2026

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

  2. CVE-2026-69804 Published Sep 8, 2026

    Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  3. CVE-2026-69724 Published Sep 8, 2026

    Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  4. CVE-2026-69716 Published Sep 8, 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  5. CVE-2026-69690 Published Sep 8, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  6. CVE-2026-69683 Published Sep 8, 2026

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

  7. CVE-2026-69636 Published Sep 8, 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

  8. CVE-2026-69615 Published Sep 8, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  9. CVE-2026-69465 Published Sep 8, 2026

    Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  10. CVE-2026-69464 Published Sep 8, 2026

    Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  11. CVE-2026-69417 Published Sep 8, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  12. CVE-2026-69409 Published Sep 8, 2026

    Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

  13. CVE-2026-69402 Published Sep 8, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  14. CVE-2026-69282 Published Sep 8, 2026

    Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  15. CVE-2026-69273 Published Sep 8, 2026

    Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  16. CVE-2026-69268 Published Sep 8, 2026

    Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  17. CVE-2026-72984 Published Aug 28, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  18. CVE-2026-70331 Published Aug 28, 2026

    Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

  19. CVE-2026-70309 Published Aug 28, 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  20. CVE-2026-66798 Published Aug 28, 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  21. CVE-2026-66324 Published Aug 28, 2026

    External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  22. CVE-2026-66323 Published Aug 28, 2026

    Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  23. CVE-2026-62904 Published Aug 28, 2026

    Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  24. CVE-2026-58616 Published Aug 28, 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.

  25. CVE-2026-70105 Published Aug 20, 2026

    Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

  26. CVE-2026-72970 Published Aug 14, 2026

    Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  27. CVE-2026-70339 Published Aug 11, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  28. CVE-2026-70355 Published Aug 11, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  29. CVE-2026-70354 Published Aug 11, 2026

    Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

  30. CVE-2026-70326 Published Aug 11, 2026

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  31. CVE-2026-70324 Published Aug 11, 2026

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  32. CVE-2026-70321 Published Aug 11, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  33. CVE-2026-70306 Published Aug 11, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  34. CVE-2026-66808 Published Aug 11, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  35. CVE-2026-66805 Published Aug 11, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  36. CVE-2026-65813 Published Aug 11, 2026

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  37. CVE-2026-65810 Published Aug 11, 2026

    Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.

  38. CVE-2026-65769 Published Aug 11, 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.

  39. CVE-2026-65768 Published Aug 11, 2026

    Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.

  40. CVE-2026-65767 Published Aug 11, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

  41. CVE-2026-65665 Published Aug 11, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  42. CVE-2026-65663 Published Aug 11, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  43. CVE-2026-65660 Published Aug 11, 2026

    Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  44. CVE-2026-65658 Published Aug 11, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  45. CVE-2026-64922 Published Aug 11, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  46. CVE-2026-64921 Published Aug 11, 2026

    Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  47. CVE-2026-64916 Published Aug 11, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  48. CVE-2026-64902 Published Aug 11, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  49. CVE-2026-64901 Published Aug 11, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  50. CVE-2026-64900 Published Aug 11, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.