Microsoft vulnerabilities

Showing 51 - 100 of 2.7K CVEs

  1. CVE-2026-64897 Published Aug 11, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  2. CVE-2026-63520 Published Aug 11, 2026

    Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

  3. CVE-2026-63516 Published Aug 11, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  4. CVE-2026-63514 Published Aug 11, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  5. CVE-2026-63512 Published Aug 11, 2026

    Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.

  6. CVE-2026-62917 Published Aug 11, 2026

    Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  7. CVE-2026-62915 Published Aug 11, 2026

    Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

  8. CVE-2026-62914 Published Aug 11, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

  9. CVE-2026-62913 Published Aug 11, 2026

    Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

  10. CVE-2026-62912 Published Aug 11, 2026

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.

  11. CVE-2026-62911 Published Aug 11, 2026

    Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  12. CVE-2026-62910 Published Aug 11, 2026

    Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  13. CVE-2026-62897 Published Aug 11, 2026

    Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

  14. CVE-2026-62872 Published Aug 11, 2026

    Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

  15. CVE-2026-62839 Published Aug 11, 2026

    Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  16. CVE-2026-62837 Published Aug 11, 2026

    Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

  17. CVE-2026-62829 Published Aug 11, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  18. CVE-2026-62827 Published Aug 11, 2026

    Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  19. CVE-2026-58639 Published Aug 11, 2026

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  20. CVE-2026-57105 Published Aug 11, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  21. CVE-2026-65667 Published Aug 7, 2026

    Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

  22. CVE-2026-62918 Published Aug 7, 2026

    Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.

  23. CVE-2026-62896 Published Aug 7, 2026

    Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

  24. CVE-2026-66326 Published Aug 4, 2026

    Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  25. CVE-2026-66325 Published Aug 4, 2026

    Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  26. CVE-2026-66322 Published Aug 4, 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  27. CVE-2026-66321 Published Aug 4, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  28. CVE-2026-66318 Published Aug 4, 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  29. CVE-2026-66317 Published Aug 4, 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

  30. CVE-2026-66316 Published Aug 4, 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  31. CVE-2026-66315 Published Aug 4, 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  32. CVE-2026-66314 Published Aug 4, 2026

    Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  33. CVE-2026-66313 Published Aug 4, 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

  34. CVE-2026-66312 Published Aug 4, 2026

    Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

  35. CVE-2026-66311 Published Aug 4, 2026

    Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

  36. CVE-2026-65804 Published Aug 4, 2026

    Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  37. CVE-2026-65802 Published Aug 4, 2026

    External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

  38. CVE-2026-57990 Published Jul 26, 2026

    Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  39. CVE-2026-57989 Published Jul 26, 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  40. CVE-2026-57978 Published Jul 26, 2026

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  41. CVE-2026-57980 Published Jul 17, 2026

    Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

  42. CVE-2026-62826 Published Jul 16, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  43. CVE-2026-50659 Published Jul 14, 2026

    Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

  44. CVE-2026-50650 Published Jul 14, 2026

    Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

  45. CVE-2026-50649 Published Jul 14, 2026

    Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

  46. CVE-2026-50648 Published Jul 14, 2026

    Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

  47. CVE-2026-50646 Published Jul 14, 2026

    Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

  48. CVE-2026-50527 Published Jul 14, 2026

    Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

  49. CVE-2026-50525 Published Jul 14, 2026

    Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

  50. CVE-2026-47304 Published Jul 14, 2026

    Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.