Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Payment Orchestrator Service Jun 17, 2026 Mar 5, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Payment Orchestrator Service Elevation of Privilege Vulnerability |
1Microsoft 1Aci Confidential Containers Jun 17, 2026 Mar 5, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 '.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. |
1Microsoft 1Aci Confidential Containers Jun 17, 2026 Mar 5, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network. |
1Microsoft 1Aci Confidential Containers Jun 17, 2026 Mar 5, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. |
1Microsoft 1Devices Pricing Program Jun 17, 2026 Mar 5, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Microsoft Devices Pricing Program Remote Code Execution Vulnerability |
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. |
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fix...Show more |
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. |
Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data su...Show more |
1Microsoft 1Confidential Sidecar Containers Jun 17, 2026 Feb 10, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network. |
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Feb 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. |
1Microsoft 1Azure Conversation Authoring Client Library Jun 17, 2026 Feb 10, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network. |
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network. |
Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. |
1Microsoft 2Exchange Server Exchange Server Subscription EditionJun 17, 2026 Feb 10, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Feb 10, 2026 N/A· v4 6.2 MEDIUM· v3 N/A· v2 Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. |
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. |
Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJun 17, 2026 Feb 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |