Microsoft
microsoft
16,005 CVEs • 1,072 products
Products (1,072)
Click to collapseToggle
Products (1,072)
Click to collapse
CVEs (16,005)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means exter...Show more |
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. |
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. |
Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. |
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. |
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. |
Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. |
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. |
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network. |
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network. |
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. |
ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for...Show more |
1Microsoft 10365 Copilot EdgeExcel+7 moreJun 17, 2026 Mar 16, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability |
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally. |
1Microsoft 1Azure Ad Ssh Login Extension For Linux Jun 17, 2026 Mar 10, 2026 N/A· v4 8.1 HIGH· v3 N/A· v2 External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally. |
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. |
1Microsoft 1Azure Automation Hybrid Worker Windows Extension Jun 17, 2026 Mar 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. |