Microsoft vulnerabilities
Showing 1 - 50 of 2.4K CVEs
- CVE-2026-57980 Published Jul 17, 2026
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
- CVE-2026-62826 Published Jul 16, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-58277 Published Jul 14, 2026
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-56192 Published Jul 14, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-56157 Published Jul 14, 2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-55142 Published Jul 14, 2026
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-55135 Published Jul 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-55134 Published Jul 14, 2026
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55132 Published Jul 14, 2026
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55130 Published Jul 14, 2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55128 Published Jul 14, 2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55127 Published Jul 14, 2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55126 Published Jul 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-55125 Published Jul 14, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-55124 Published Jul 14, 2026
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-55121 Published Jul 14, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-55055 Published Jul 14, 2026
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55054 Published Jul 14, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- CVE-2026-55052 Published Jul 14, 2026
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-55051 Published Jul 14, 2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
- CVE-2026-55050 Published Jul 14, 2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-55047 Published Jul 14, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-55045 Published Jul 14, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-55038 Published Jul 14, 2026
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55040 Published Jul 14, 2026
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-55035 Published Jul 14, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-55034 Published Jul 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-55033 Published Jul 14, 2026
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55032 Published Jul 14, 2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-55030 Published Jul 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-55028 Published Jul 14, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-55027 Published Jul 14, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-55026 Published Jul 14, 2026
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-55023 Published Jul 14, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-55021 Published Jul 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-55020 Published Jul 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-55019 Published Jul 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-55016 Published Jul 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-58644 Published Jul 14, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-54108 Published Jul 14, 2026
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-50522 Published Jul 14, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-58596 Published Jul 12, 2026
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-58281 Published Jul 11, 2026
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-58525 Published Jul 8, 2026
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-58523 Published Jul 3, 2026
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-58597 Published Jul 3, 2026
Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-58524 Published Jul 3, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-58522 Published Jul 3, 2026
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
- CVE-2026-58300 Published Jul 3, 2026
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
- CVE-2026-58299 Published Jul 3, 2026
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
medium 5.4
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
high 8.8
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium 5.5
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 5.4
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
medium 5.5
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
high 7.3
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 7.8
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
medium 5.5
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium 5.5
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
medium 6.5
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
high 8.8
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
medium 6.5
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
medium 5.5
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium 5.5
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
critical 9.1
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium 5.5
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
high 7.3
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium 5.5
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium 5.5
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium 6.2
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium 5.5
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
high 7.3
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
critical 9.8
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 6.5
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
critical 9.8
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
high 8.3
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high 8.3
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
high 8.2
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
medium 6.5
Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium 4.3
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
medium 6.8
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
medium 6.2
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
high 7.5