Microsoft vulnerabilities

Showing 151 - 200 of 2.7K CVEs

  1. CVE-2026-58596 Published Jul 12, 2026

    Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

  2. CVE-2026-58281 Published Jul 11, 2026

    Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  3. CVE-2026-58525 Published Jul 8, 2026

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  4. CVE-2026-58523 Published Jul 3, 2026

    Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

  5. CVE-2026-58597 Published Jul 3, 2026

    Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  6. CVE-2026-58524 Published Jul 3, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  7. CVE-2026-58522 Published Jul 3, 2026

    Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

  8. CVE-2026-58300 Published Jul 3, 2026

    Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

  9. CVE-2026-58299 Published Jul 3, 2026

    Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.

  10. CVE-2026-58298 Published Jul 3, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  11. CVE-2026-58297 Published Jul 3, 2026

    Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

  12. CVE-2026-58296 Published Jul 3, 2026

    Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

  13. CVE-2026-58295 Published Jul 3, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  14. CVE-2026-58294 Published Jul 3, 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  15. CVE-2026-58293 Published Jul 3, 2026

    External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  16. CVE-2026-58292 Published Jul 3, 2026

    Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  17. CVE-2026-58291 Published Jul 3, 2026

    Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  18. CVE-2026-58290 Published Jul 3, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  19. CVE-2026-58289 Published Jul 3, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  20. CVE-2026-58288 Published Jul 3, 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  21. CVE-2026-58287 Published Jul 3, 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  22. CVE-2026-58286 Published Jul 3, 2026

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  23. CVE-2026-58285 Published Jul 3, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  24. CVE-2026-58284 Published Jul 3, 2026

    Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  25. CVE-2026-58283 Published Jul 3, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  26. CVE-2026-58282 Published Jul 3, 2026

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  27. CVE-2026-58278 Published Jul 3, 2026

    Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  28. CVE-2026-58276 Published Jul 3, 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  29. CVE-2026-57993 Published Jul 3, 2026

    Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  30. CVE-2026-57992 Published Jul 3, 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  31. CVE-2026-57991 Published Jul 3, 2026

    Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  32. CVE-2026-57988 Published Jul 3, 2026

    Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  33. CVE-2026-57987 Published Jul 3, 2026

    Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  34. CVE-2026-57986 Published Jul 3, 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  35. CVE-2026-57985 Published Jul 3, 2026

    Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  36. CVE-2026-57984 Published Jul 3, 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  37. CVE-2026-57983 Published Jul 3, 2026

    Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  38. CVE-2026-57981 Published Jul 3, 2026

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  39. CVE-2026-57977 Published Jul 3, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  40. CVE-2026-57975 Published Jul 3, 2026

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  41. CVE-2026-57974 Published Jul 3, 2026

    Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  42. CVE-2026-56646 Published Jul 3, 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  43. CVE-2026-56645 Published Jul 3, 2026

    Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  44. CVE-2026-55945 Published Jul 3, 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

  45. CVE-2026-45489 Published Jul 3, 2026

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  46. CVE-2026-45488 Published Jul 3, 2026

    User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  47. CVE-2026-50521 Published Jul 1, 2026

    Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

  48. CVE-2026-32208 Published Jun 19, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.

  49. CVE-2026-48562 Published Jun 9, 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  50. CVE-2026-48560 Published Jun 9, 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.