Microsoft vulnerabilities
Showing 101 - 150 of 2.4K CVEs
- CVE-2026-47293 Published Jun 9, 2026
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
- CVE-2026-45583 Published Jun 9, 2026
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-45504 Published Jun 9, 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-45503 Published Jun 9, 2026
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
- CVE-2026-45502 Published Jun 9, 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
- CVE-2026-45501 Published Jun 9, 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45500 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-45485 Published Jun 9, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-45484 Published Jun 9, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-45483 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45481 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45479 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45475 Published Jun 9, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-45471 Published Jun 9, 2026
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-45468 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45467 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45465 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-45464 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-45462 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45458 Published Jun 9, 2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-45456 Published Jun 9, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-45454 Published Jun 9, 2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-45453 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-44824 Published Jun 9, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-44821 Published Jun 9, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-44819 Published Jun 9, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-42835 Published Jun 9, 2026
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
- CVE-2026-33113 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-47294 Published Jun 1, 2026
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-45659 Published May 22, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-45495 Published May 18, 2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2026-45494 Published May 18, 2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2026-45492 Published May 18, 2026
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-42897 Published May 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-42891 Published May 12, 2026
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-42838 Published May 12, 2026
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-42832 Published May 12, 2026
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
- CVE-2026-42831 Published May 12, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-41107 Published May 12, 2026
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- CVE-2026-40421 Published May 12, 2026
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-40420 Published May 12, 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
- CVE-2026-40419 Published May 12, 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
- CVE-2026-40418 Published May 12, 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
- CVE-2026-40416 Published May 12, 2026
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-40368 Published May 12, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-40367 Published May 12, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-40366 Published May 12, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-40365 Published May 12, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-40364 Published May 12, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-40363 Published May 12, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
high 7.0
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
high 7.5
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
high 8.8
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
high 8.1
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
medium 5.0
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
medium 6.5
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
medium 6.1
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
low 3.3
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
high 8.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
high 7.3
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 7.8
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
medium 6.5
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 7.8
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium 5.5
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 7.8
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
high 8.1
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.0
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high 8.8
Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium 5.4
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
medium 5.4
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
high 8.1
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium 6.5
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
medium 5.4
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
high 7.7
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 7.8
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
high 7.4
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
medium 4.3
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
high 8.8
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
high 7.8
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
high 7.8
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium 4.3
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.0
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 8.4
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 8.4
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 8.4
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4