Microsoft
microsoft
16,005 CVEs • 1,072 products
Products (1,072)
Click to collapseToggle
Products (1,072)
Click to collapse
CVEs (16,005)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fix...Show more |
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. |
Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data su...Show more |
1Microsoft 1Confidential Sidecar Containers Jun 17, 2026 Feb 10, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network. |
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Feb 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. |
1Microsoft 1Azure Conversation Authoring Client Library Jun 17, 2026 Feb 10, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network. |
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network. |
Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. |
1Microsoft 2Exchange Server Exchange Server Subscription EditionJun 17, 2026 Feb 10, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Feb 10, 2026 N/A· v4 6.2 MEDIUM· v3 N/A· v2 Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally. |
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. |
Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. |
1Microsoft 12Windows 10 1607 Windows 10 1809Windows 10 21h2+9 moreJun 17, 2026 Feb 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. |
Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally. |
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network. |
1Microsoft 2365 Apps Office Long Term Servicing ChannelJun 17, 2026 Feb 10, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Feb 10, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. |
Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network. |