Microsoft vulnerabilities

Showing 101 - 150 of 2.4K CVEs

  1. CVE-2026-47293 Published Jun 9, 2026

    Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

  2. CVE-2026-45583 Published Jun 9, 2026

    Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

  3. CVE-2026-45504 Published Jun 9, 2026

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  4. CVE-2026-45503 Published Jun 9, 2026

    Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

  5. CVE-2026-45502 Published Jun 9, 2026

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

  6. CVE-2026-45501 Published Jun 9, 2026

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

  7. CVE-2026-45500 Published Jun 9, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  8. CVE-2026-45485 Published Jun 9, 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

  9. CVE-2026-45484 Published Jun 9, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  10. CVE-2026-45483 Published Jun 9, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.

  11. CVE-2026-45481 Published Jun 9, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  12. CVE-2026-45479 Published Jun 9, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  13. CVE-2026-45475 Published Jun 9, 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  14. CVE-2026-45471 Published Jun 9, 2026

    Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  15. CVE-2026-45468 Published Jun 9, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  16. CVE-2026-45467 Published Jun 9, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  17. CVE-2026-45465 Published Jun 9, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  18. CVE-2026-45464 Published Jun 9, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  19. CVE-2026-45462 Published Jun 9, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  20. CVE-2026-45458 Published Jun 9, 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  21. CVE-2026-45456 Published Jun 9, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

  22. CVE-2026-45454 Published Jun 9, 2026

    Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  23. CVE-2026-45453 Published Jun 9, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  24. CVE-2026-44824 Published Jun 9, 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  25. CVE-2026-44821 Published Jun 9, 2026

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

  26. CVE-2026-44819 Published Jun 9, 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  27. CVE-2026-42835 Published Jun 9, 2026

    Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

  28. CVE-2026-33113 Published Jun 9, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  29. CVE-2026-47294 Published Jun 1, 2026

    Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  30. CVE-2026-45659 Published May 22, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  31. CVE-2026-45495 Published May 18, 2026

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  32. CVE-2026-45494 Published May 18, 2026

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  33. CVE-2026-45492 Published May 18, 2026

    Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  34. CVE-2026-42897 Published May 14, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  35. CVE-2026-42891 Published May 12, 2026

    User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  36. CVE-2026-42838 Published May 12, 2026

    Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

  37. CVE-2026-42832 Published May 12, 2026

    Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

  38. CVE-2026-42831 Published May 12, 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  39. CVE-2026-41107 Published May 12, 2026

    External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  40. CVE-2026-40421 Published May 12, 2026

    Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  41. CVE-2026-40420 Published May 12, 2026

    Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

  42. CVE-2026-40419 Published May 12, 2026

    Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

  43. CVE-2026-40418 Published May 12, 2026

    Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

  44. CVE-2026-40416 Published May 12, 2026

    User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  45. CVE-2026-40368 Published May 12, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  46. CVE-2026-40367 Published May 12, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  47. CVE-2026-40366 Published May 12, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  48. CVE-2026-40365 Published May 12, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  49. CVE-2026-40364 Published May 12, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  50. CVE-2026-40363 Published May 12, 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.