Microsoft vulnerabilities
Showing 251 - 300 of 2.4K CVEs
- CVE-2025-59231 Published Oct 14, 2025
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-59228 Published Oct 14, 2025
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2025-59225 Published Oct 14, 2025
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-59227 Published Oct 14, 2025
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-59224 Published Oct 14, 2025
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-59223 Published Oct 14, 2025
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-59222 Published Oct 14, 2025
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-59221 Published Oct 14, 2025
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-53782 Published Oct 14, 2025
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
- CVE-2025-55248 Published Oct 14, 2025
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
- CVE-2025-59251 Published Sep 24, 2025
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2025-54910 Published Sep 9, 2025
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-54908 Published Sep 9, 2025
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- CVE-2025-54907 Published Sep 9, 2025
Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
- CVE-2025-54906 Published Sep 9, 2025
Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-54905 Published Sep 9, 2025
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2025-54904 Published Sep 9, 2025
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-54903 Published Sep 9, 2025
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-54902 Published Sep 9, 2025
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-54901 Published Sep 9, 2025
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2025-54900 Published Sep 9, 2025
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-54899 Published Sep 9, 2025
Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-54898 Published Sep 9, 2025
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-54897 Published Sep 9, 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2025-54896 Published Sep 9, 2025
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-53791 Published Sep 5, 2025
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2025-53761 Published Aug 12, 2025
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
- CVE-2025-53766 Published Aug 12, 2025
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- CVE-2025-53759 Published Aug 12, 2025
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-53741 Published Aug 12, 2025
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-53740 Published Aug 12, 2025
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-53739 Published Aug 12, 2025
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-53738 Published Aug 12, 2025
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-53760 Published Aug 12, 2025
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2025-53734 Published Aug 12, 2025
Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
- CVE-2025-53733 Published Aug 12, 2025
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2025-53737 Published Aug 12, 2025
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-53732 Published Aug 12, 2025
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-53735 Published Aug 12, 2025
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-53736 Published Aug 12, 2025
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2025-53730 Published Aug 12, 2025
Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
- CVE-2025-53731 Published Aug 12, 2025
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2025-50154 Published Aug 12, 2025
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-49712 Published Aug 12, 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2025-33051 Published Aug 12, 2025
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
- CVE-2025-25005 Published Aug 12, 2025
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
- CVE-2025-25007 Published Aug 12, 2025
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-25006 Published Aug 12, 2025
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-53786 Published Aug 6, 2025
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment.
- CVE-2025-53771 Published Jul 20, 2025
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.0
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
high 8.4
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
medium 4.8
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
high 7.6
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
high 7.8
Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
high 7.8
Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.
high 7.8
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
high 7.1
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
medium 5.5
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
medium 4.7
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
high 7.8
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
critical 9.8
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 7.8
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
high 7.1
Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
high 7.8
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high 8.4
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high 7.8
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
medium 6.8
Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
high 7.8
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
high 8.4
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
medium 6.5
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
high 8.8
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
high 7.5
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
medium 6.5
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
medium 5.3
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
medium 5.3
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment.
high 8.0
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium 6.5