Microsoft
microsoft
16,005 CVEs • 1,072 products
Products (1,072)
Click to collapseToggle
Products (1,072)
Click to collapse
CVEs (16,005)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 Mar 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Mar 10, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 Mar 10, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in RPC Runtime allows an authorized attacker to execute code over a network. |
1Microsoft 10Windows 10 1607 Windows 10 1809Windows 10 21h2+7 moreJun 17, 2026 Mar 10, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
1Microsoft 7Windows 10 1809 Windows 10 21h2Windows 10 22h2+4 moreJun 17, 2026 Mar 10, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. |
2Microsof Microsoft2Linux Diagnostic Extension Linux Diagnostic ExtensionJun 17, 2026 Mar 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally. |
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. |
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. |
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. |
Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. |
Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network. |
Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network. |
1Microsoft 5Sql Server 2016 Sql Server 2017Sql Server 2019+2 moreJul 10, 2026 Mar 10, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
1Microsoft 1System Center Operations Manager Jun 17, 2026 Mar 10, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. |
1Microsoft 1Payment Orchestrator Service Jun 17, 2026 Mar 5, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Payment Orchestrator Service Elevation of Privilege Vulnerability |
1Microsoft 1Aci Confidential Containers Jun 17, 2026 Mar 5, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 '.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. |
1Microsoft 1Aci Confidential Containers Jun 17, 2026 Mar 5, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network. |
1Microsoft 1Aci Confidential Containers Jun 17, 2026 Mar 5, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. |
1Microsoft 1Devices Pricing Program Jun 17, 2026 Mar 5, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Microsoft Devices Pricing Program Remote Code Execution Vulnerability |
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. |