Microsoft vulnerabilities
Showing 151 - 200 of 2.4K CVEs
- CVE-2026-40362 Published May 12, 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-40361 Published May 12, 2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-40360 Published May 12, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-40359 Published May 12, 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-40358 Published May 12, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-40357 Published May 12, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-35440 Published May 12, 2026
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-35439 Published May 12, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-35436 Published May 12, 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
- CVE-2026-35433 Published May 12, 2026
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-33112 Published May 12, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-33110 Published May 12, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-32185 Published May 12, 2026
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
- CVE-2026-32177 Published May 12, 2026
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-33823 Published May 7, 2026
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
- CVE-2026-33116 Published Apr 14, 2026
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
- CVE-2026-32226 Published Apr 14, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
- CVE-2026-32201 Published Apr 14, 2026
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-32200 Published Apr 14, 2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- CVE-2026-32199 Published Apr 14, 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-32198 Published Apr 14, 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-32197 Published Apr 14, 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-32190 Published Apr 14, 2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-32189 Published Apr 14, 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-32188 Published Apr 14, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-23666 Published Apr 14, 2026
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
- CVE-2026-20945 Published Apr 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-33118 Published Apr 10, 2026
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-26133 Published Mar 16, 2026
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
- CVE-2026-0385 Published Mar 16, 2026
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
- CVE-2026-26114 Published Mar 10, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-26113 Published Mar 10, 2026
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-26112 Published Mar 10, 2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-26110 Published Mar 10, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-26109 Published Mar 10, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-26108 Published Mar 10, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-26107 Published Mar 10, 2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-26106 Published Mar 10, 2026
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-26105 Published Mar 10, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-21535 Published Feb 19, 2026
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
- CVE-2026-0102 Published Feb 17, 2026
Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.
- CVE-2026-21527 Published Feb 10, 2026
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-21511 Published Feb 10, 2026
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-21261 Published Feb 10, 2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-21260 Published Feb 10, 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-21259 Published Feb 10, 2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-21258 Published Feb 10, 2026
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-0391 Published Feb 5, 2026
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-21509 Published Jan 26, 2026
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
- CVE-2026-21223 Published Jan 16, 2026
Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
high 7.8
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
medium 5.5
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
high 8.8
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
high 7.3
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
medium 5.5
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
high 7.3
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
critical 9.6
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
high 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
medium 5.9
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium 6.5
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
high 7.1
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
high 7.5
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium 4.3
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
high 7.1
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
medium 5.0
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 8.4
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
high 8.1
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
high 8.2
Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.
low 3.1
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
medium 6.5
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
high 7.5
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
medium 5.5
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
high 7.5
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.
high 7.8
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
medium 5.5
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
medium 6.5
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
high 7.8
Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
high 7.1