Microsoft vulnerabilities

Showing 151 - 200 of 2.4K CVEs

  1. CVE-2026-40362 Published May 12, 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  2. CVE-2026-40361 Published May 12, 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  3. CVE-2026-40360 Published May 12, 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  4. CVE-2026-40359 Published May 12, 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  5. CVE-2026-40358 Published May 12, 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  6. CVE-2026-40357 Published May 12, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  7. CVE-2026-35440 Published May 12, 2026

    Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  8. CVE-2026-35439 Published May 12, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  9. CVE-2026-35436 Published May 12, 2026

    Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

  10. CVE-2026-35433 Published May 12, 2026

    Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

  11. CVE-2026-33112 Published May 12, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  12. CVE-2026-33110 Published May 12, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  13. CVE-2026-32185 Published May 12, 2026

    Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.

  14. CVE-2026-32177 Published May 12, 2026

    Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

  15. CVE-2026-33823 Published May 7, 2026

    Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

  16. CVE-2026-33116 Published Apr 14, 2026

    Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

  17. CVE-2026-32226 Published Apr 14, 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.

  18. CVE-2026-32201 Published Apr 14, 2026

    Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  19. CVE-2026-32200 Published Apr 14, 2026

    Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

  20. CVE-2026-32199 Published Apr 14, 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  21. CVE-2026-32198 Published Apr 14, 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  22. CVE-2026-32197 Published Apr 14, 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  23. CVE-2026-32190 Published Apr 14, 2026

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  24. CVE-2026-32189 Published Apr 14, 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  25. CVE-2026-32188 Published Apr 14, 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  26. CVE-2026-23666 Published Apr 14, 2026

    Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.

  27. CVE-2026-20945 Published Apr 14, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  28. CVE-2026-33118 Published Apr 10, 2026

    User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  29. CVE-2026-26133 Published Mar 16, 2026

    AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  30. CVE-2026-0385 Published Mar 16, 2026

    Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

  31. CVE-2026-26114 Published Mar 10, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  32. CVE-2026-26113 Published Mar 10, 2026

    Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

  33. CVE-2026-26112 Published Mar 10, 2026

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  34. CVE-2026-26110 Published Mar 10, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

  35. CVE-2026-26109 Published Mar 10, 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  36. CVE-2026-26108 Published Mar 10, 2026

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  37. CVE-2026-26107 Published Mar 10, 2026

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  38. CVE-2026-26106 Published Mar 10, 2026

    Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  39. CVE-2026-26105 Published Mar 10, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  40. CVE-2026-21535 Published Feb 19, 2026

    Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.

  41. CVE-2026-0102 Published Feb 17, 2026

    Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.

  42. CVE-2026-21527 Published Feb 10, 2026

    User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  43. CVE-2026-21511 Published Feb 10, 2026

    Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

  44. CVE-2026-21261 Published Feb 10, 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  45. CVE-2026-21260 Published Feb 10, 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

  46. CVE-2026-21259 Published Feb 10, 2026

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.

  47. CVE-2026-21258 Published Feb 10, 2026

    Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  48. CVE-2026-0391 Published Feb 5, 2026

    User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

  49. CVE-2026-21509 Published Jan 26, 2026

    Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

  50. CVE-2026-21223 Published Jan 16, 2026

    Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.