Microsoft
microsoft
14,958 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,958)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Exchange Server Exchange Server Subscription EditionJun 17, 2026 Aug 12, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
1Microsoft 2Exchange Server Exchange Server Subscription EditionJun 17, 2026 Aug 12, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. |
1Microsoft 4Sql Server 2016 Sql Server 2017Sql Server 2019+1 moreJun 17, 2026 Aug 12, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
Azure Portal Elevation of Privilege Vulnerability |
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |
Azure OpenAI Elevation of Privilege Vulnerability |
1Microsoft 2Exchange Server Exchange Server Subscription EditionJun 17, 2026 Aug 6, 2025 N/A· v4 8.0 HIGH· v3 N/A· v2 On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hyb...Show more |
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Micro...Show more |
Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network. |
Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. |
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Jul 8, 2025 N/A· v4 3.5 LOW· v3 N/A· v2 External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network. |
Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally. |