← Back

Microsoft

microsoft

14,951 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,951)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Excel
Apr 16, 2026
Oct 1, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.
1Microsoft
1Internet Explorer
Apr 16, 2026
Sep 24, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.
1Microsoft
1Msn Setup Bulletin Board Services
Apr 16, 2026
Sep 24, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.
1Microsoft
2Commercial Internet System
Internet Information Server
Apr 16, 2026
Sep 23, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.
1Microsoft
4Terminal Server
Windows 95Windows 98se+1 more
Apr 16, 2026
Sep 20, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.
1Microsoft
1Windows Nt
Apr 16, 2026
Sep 17, 1999
N/A· v4
N/A· v3
9.0 HIGH· v2
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
1Microsoft
1Hotmail
Apr 16, 2026
Sep 13, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account.
1Microsoft
1Internet Explorer
Apr 16, 2026
Sep 10, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration...Show more
The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active Setup (setupctl.dll) ActiveX controls for Internet Explorer (IE) 4.01 and 5.0 are marked as "Safe for Scripting," which allows remote attackers to create and modify files and execute arbitrary commands.Show less
1Microsoft
3Commercial Internet System
Site ServerSite Server Commerce
Apr 16, 2026
Sep 10, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.
1Microsoft
1Internet Explorer
Apr 16, 2026
Sep 10, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.
1Microsoft
1Internet Explorer
Apr 16, 2026
Sep 1, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.
1Microsoft
1Internet Explorer
Apr 16, 2026
Sep 1, 1999
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.
1Microsoft
1Internet Explorer
Apr 16, 2026
Sep 1, 1999
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.
2Microsoft
Qualcomm
4Eudora
FrontpageInternet Explorer+1 more
Apr 16, 2026
Aug 27, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service...Show more
Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Aug 25, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observ...Show more
Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.Show less
1Microsoft
1Windows Nt
Apr 16, 2026
Aug 24, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.
1Microsoft
1Frontpage
Apr 16, 2026
Aug 24, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive informati...Show more
Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.Show less
1Microsoft
1Internet Explorer
Apr 16, 2026
Aug 21, 1999
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.
1Microsoft
1Jet
Apr 16, 2026
Aug 20, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.
1Microsoft
1Internet Information Server
Apr 16, 2026
Aug 19, 1999
N/A· v4
N/A· v3
7.1 HIGH· v2
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".