Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Azure Core Shared Client Library Azure Sdk For PythonJun 17, 2026 Jan 13, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Jan 13, 2026 N/A· v4 6.4 MEDIUM· v3 N/A· v2 Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure B...Show more |
1Microsoft 1Azure Connected Machine Agent Jun 17, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. |
1Microsoft 3Windows 11 24h2 Windows 11 25h2Windows Server 2025Jun 17, 2026 Jan 13, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. |
1Microsoft 1Windows Software Development Kit Jun 17, 2026 Jan 13, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. |
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally. |
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreJun 17, 2026 Jan 13, 2026 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. |
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. |
1Microsoft 5365 Apps ExcelOffice+2 moreJun 17, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
1Microsoft 2365 Apps Office Long Term Servicing ChannelJun 17, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreJun 17, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 Jan 13, 2026 N/A· v4 8.4 HIGH· v3 N/A· v2 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 17, 2026 Jan 13, 2026 N/A· v4 8.4 HIGH· v3 N/A· v2 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. |
1Microsoft 5365 Apps ExcelOffice+2 moreJun 17, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
1Microsoft 2365 Apps Office Long Term Servicing ChannelJun 17, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreJun 17, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |