Microsoft vulnerabilities
Showing 51 - 100 of 2.7K CVEs
- CVE-2026-64897 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-63520 Published Aug 11, 2026
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-63516 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-63514 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-63512 Published Aug 11, 2026
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
- CVE-2026-62917 Published Aug 11, 2026
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-62915 Published Aug 11, 2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
- CVE-2026-62914 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
- CVE-2026-62913 Published Aug 11, 2026
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
- CVE-2026-62912 Published Aug 11, 2026
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
- CVE-2026-62911 Published Aug 11, 2026
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-62910 Published Aug 11, 2026
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-62897 Published Aug 11, 2026
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
- CVE-2026-62872 Published Aug 11, 2026
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
- CVE-2026-62839 Published Aug 11, 2026
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-62837 Published Aug 11, 2026
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
- CVE-2026-62829 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-62827 Published Aug 11, 2026
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-58639 Published Aug 11, 2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-57105 Published Aug 11, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-65667 Published Aug 7, 2026
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-62918 Published Aug 7, 2026
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-62896 Published Aug 7, 2026
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
- CVE-2026-66326 Published Aug 4, 2026
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-66325 Published Aug 4, 2026
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-66322 Published Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-66321 Published Aug 4, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-66318 Published Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- CVE-2026-66317 Published Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
- CVE-2026-66316 Published Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-66315 Published Aug 4, 2026
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-66314 Published Aug 4, 2026
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- CVE-2026-66313 Published Aug 4, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
- CVE-2026-66312 Published Aug 4, 2026
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
- CVE-2026-66311 Published Aug 4, 2026
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
- CVE-2026-65804 Published Aug 4, 2026
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-65802 Published Aug 4, 2026
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
- CVE-2026-57990 Published Jul 26, 2026
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- CVE-2026-57989 Published Jul 26, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- CVE-2026-57978 Published Jul 26, 2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-57980 Published Jul 17, 2026
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
- CVE-2026-62826 Published Jul 16, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-50659 Published Jul 14, 2026
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
- CVE-2026-50650 Published Jul 14, 2026
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-50649 Published Jul 14, 2026
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
- CVE-2026-50648 Published Jul 14, 2026
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
- CVE-2026-50646 Published Jul 14, 2026
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
- CVE-2026-50527 Published Jul 14, 2026
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
- CVE-2026-50525 Published Jul 14, 2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- CVE-2026-47304 Published Jul 14, 2026
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
high 8.1
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 6.5
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
medium 6.5
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
medium 6.5
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
high 7.3
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
high 8.8
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
medium 6.5
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
high 8.0
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
high 7.2
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
high 7.0
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
high 8.8
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 6.5
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
medium 6.5
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
high 8.8
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 6.5
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
high 8.0
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
critical 10.0
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
high 7.5
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
critical 9.6
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
medium 6.5
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium 6.1
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
high 7.1
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high 7.4
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
high 8.1
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
medium 5.4
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
high 7.5
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
medium 6.5
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
medium 6.8
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
medium 6.5
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
medium 6.2
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium 6.1
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
high 7.4
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
high 7.4
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
high 7.4
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
medium 5.4
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
medium 6.5
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
high 7.8
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
high 7.8
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
high 7.5
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
high 7.8
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
high 7.5
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
high 7.5
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
high 8.1