Microsoft vulnerabilities
Showing 201 - 250 of 2.7K CVEs
- CVE-2026-47641 Published Jun 9, 2026
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-47640 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-47639 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-47638 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-47637 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-47636 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-47634 Published Jun 9, 2026
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-47631 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-47298 Published Jun 9, 2026
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-47293 Published Jun 9, 2026
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
- CVE-2026-45583 Published Jun 9, 2026
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-45504 Published Jun 9, 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-45503 Published Jun 9, 2026
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
- CVE-2026-45502 Published Jun 9, 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
- CVE-2026-45501 Published Jun 9, 2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45500 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-45485 Published Jun 9, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-45484 Published Jun 9, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-45483 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45481 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45479 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45475 Published Jun 9, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-45471 Published Jun 9, 2026
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-45468 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45467 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45465 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-45464 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-45462 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45458 Published Jun 9, 2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-45456 Published Jun 9, 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-45454 Published Jun 9, 2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-45453 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-44824 Published Jun 9, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-44821 Published Jun 9, 2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-44819 Published Jun 9, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-42835 Published Jun 9, 2026
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
- CVE-2026-33113 Published Jun 9, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-47294 Published Jun 1, 2026
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-45659 Published May 22, 2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-45495 Published May 18, 2026
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2026-45494 Published May 18, 2026
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2026-45492 Published May 18, 2026
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-42897 Published May 14, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-42891 Published May 12, 2026
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-42838 Published May 12, 2026
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-42832 Published May 12, 2026
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
- CVE-2026-42831 Published May 12, 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-41107 Published May 12, 2026
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- CVE-2026-40421 Published May 12, 2026
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2026-40420 Published May 12, 2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
high 7.3
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
high 8.1
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.0
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
high 7.0
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
high 7.5
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
high 8.8
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
high 8.1
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
medium 5.0
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
medium 6.5
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
medium 6.1
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
low 3.3
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
high 8.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
high 7.3
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 7.8
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
medium 4.6
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
medium 6.5
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 7.8
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
medium 5.5
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 7.8
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
high 8.1
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium 5.4
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.0
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high 8.8
Microsoft Edge (Chromium-based) Spoofing Vulnerability
medium 5.4
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
medium 5.4
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
high 8.1
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
medium 6.5
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
medium 5.4
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
high 7.7
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 7.8
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
high 7.4
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
medium 4.3
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
high 8.8