Microsoft vulnerabilities

Showing 1 - 50 of 2.4K CVEs

  1. CVE-2026-57980 Published Jul 17, 2026

    Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

  2. CVE-2026-62826 Published Jul 16, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  3. CVE-2026-58277 Published Jul 14, 2026

    Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  4. CVE-2026-56192 Published Jul 14, 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

  5. CVE-2026-56157 Published Jul 14, 2026

    Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  6. CVE-2026-55142 Published Jul 14, 2026

    Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  7. CVE-2026-55135 Published Jul 14, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  8. CVE-2026-55134 Published Jul 14, 2026

    Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  9. CVE-2026-55132 Published Jul 14, 2026

    Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  10. CVE-2026-55130 Published Jul 14, 2026

    Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  11. CVE-2026-55128 Published Jul 14, 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  12. CVE-2026-55127 Published Jul 14, 2026

    Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  13. CVE-2026-55126 Published Jul 14, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  14. CVE-2026-55125 Published Jul 14, 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  15. CVE-2026-55124 Published Jul 14, 2026

    Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  16. CVE-2026-55121 Published Jul 14, 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

  17. CVE-2026-55055 Published Jul 14, 2026

    Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  18. CVE-2026-55054 Published Jul 14, 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

  19. CVE-2026-55052 Published Jul 14, 2026

    Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  20. CVE-2026-55051 Published Jul 14, 2026

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

  21. CVE-2026-55050 Published Jul 14, 2026

    Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  22. CVE-2026-55047 Published Jul 14, 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

  23. CVE-2026-55045 Published Jul 14, 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

  24. CVE-2026-55038 Published Jul 14, 2026

    Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  25. CVE-2026-55040 Published Jul 14, 2026

    Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

  26. CVE-2026-55035 Published Jul 14, 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

  27. CVE-2026-55034 Published Jul 14, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  28. CVE-2026-55033 Published Jul 14, 2026

    Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  29. CVE-2026-55032 Published Jul 14, 2026

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  30. CVE-2026-55030 Published Jul 14, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  31. CVE-2026-55028 Published Jul 14, 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

  32. CVE-2026-55027 Published Jul 14, 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

  33. CVE-2026-55026 Published Jul 14, 2026

    Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

  34. CVE-2026-55023 Published Jul 14, 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

  35. CVE-2026-55021 Published Jul 14, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  36. CVE-2026-55020 Published Jul 14, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  37. CVE-2026-55019 Published Jul 14, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  38. CVE-2026-55016 Published Jul 14, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  39. CVE-2026-58644 Published Jul 14, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

  40. CVE-2026-54108 Published Jul 14, 2026

    External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  41. CVE-2026-50522 Published Jul 14, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

  42. CVE-2026-58596 Published Jul 12, 2026

    Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

  43. CVE-2026-58281 Published Jul 11, 2026

    Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  44. CVE-2026-58525 Published Jul 8, 2026

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  45. CVE-2026-58523 Published Jul 3, 2026

    Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

  46. CVE-2026-58597 Published Jul 3, 2026

    Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  47. CVE-2026-58524 Published Jul 3, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  48. CVE-2026-58522 Published Jul 3, 2026

    Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

  49. CVE-2026-58300 Published Jul 3, 2026

    Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

  50. CVE-2026-58299 Published Jul 3, 2026

    Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.