Microsoft vulnerabilities

Showing 251 - 300 of 2.4K CVEs

  1. CVE-2025-59231 Published Oct 14, 2025

    Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  2. CVE-2025-59228 Published Oct 14, 2025

    Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  3. CVE-2025-59225 Published Oct 14, 2025

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  4. CVE-2025-59227 Published Oct 14, 2025

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  5. CVE-2025-59224 Published Oct 14, 2025

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  6. CVE-2025-59223 Published Oct 14, 2025

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  7. CVE-2025-59222 Published Oct 14, 2025

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  8. CVE-2025-59221 Published Oct 14, 2025

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  9. CVE-2025-53782 Published Oct 14, 2025

    Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

  10. CVE-2025-55248 Published Oct 14, 2025

    Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

  11. CVE-2025-59251 Published Sep 24, 2025

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  12. CVE-2025-54910 Published Sep 9, 2025

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  13. CVE-2025-54908 Published Sep 9, 2025

    Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

  14. CVE-2025-54907 Published Sep 9, 2025

    Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

  15. CVE-2025-54906 Published Sep 9, 2025

    Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.

  16. CVE-2025-54905 Published Sep 9, 2025

    Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  17. CVE-2025-54904 Published Sep 9, 2025

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  18. CVE-2025-54903 Published Sep 9, 2025

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  19. CVE-2025-54902 Published Sep 9, 2025

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  20. CVE-2025-54901 Published Sep 9, 2025

    Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  21. CVE-2025-54900 Published Sep 9, 2025

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  22. CVE-2025-54899 Published Sep 9, 2025

    Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  23. CVE-2025-54898 Published Sep 9, 2025

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  24. CVE-2025-54897 Published Sep 9, 2025

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  25. CVE-2025-54896 Published Sep 9, 2025

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  26. CVE-2025-53791 Published Sep 5, 2025

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  27. CVE-2025-53761 Published Aug 12, 2025

    Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

  28. CVE-2025-53766 Published Aug 12, 2025

    Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

  29. CVE-2025-53759 Published Aug 12, 2025

    Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  30. CVE-2025-53741 Published Aug 12, 2025

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  31. CVE-2025-53740 Published Aug 12, 2025

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  32. CVE-2025-53739 Published Aug 12, 2025

    Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  33. CVE-2025-53738 Published Aug 12, 2025

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  34. CVE-2025-53760 Published Aug 12, 2025

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  35. CVE-2025-53734 Published Aug 12, 2025

    Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

  36. CVE-2025-53733 Published Aug 12, 2025

    Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  37. CVE-2025-53737 Published Aug 12, 2025

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  38. CVE-2025-53732 Published Aug 12, 2025

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  39. CVE-2025-53735 Published Aug 12, 2025

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  40. CVE-2025-53736 Published Aug 12, 2025

    Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  41. CVE-2025-53730 Published Aug 12, 2025

    Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

  42. CVE-2025-53731 Published Aug 12, 2025

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  43. CVE-2025-50154 Published Aug 12, 2025

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

  44. CVE-2025-49712 Published Aug 12, 2025

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  45. CVE-2025-33051 Published Aug 12, 2025

    Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

  46. CVE-2025-25005 Published Aug 12, 2025

    Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

  47. CVE-2025-25007 Published Aug 12, 2025

    Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  48. CVE-2025-25006 Published Aug 12, 2025

    Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  49. CVE-2025-53786 Published Aug 6, 2025

    On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment.

  50. CVE-2025-53771 Published Jul 20, 2025

    Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.