Microsoft
microsoft
16,005 CVEs • 1,072 products
Products (1,072)
Click to collapseToggle
Products (1,072)
Click to collapse
CVEs (16,005)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. |
Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject` function copies properties from source objects without proper validati...Show more |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelJun 25, 2026 Jan 26, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. |
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. |
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. |
Azure Entra ID Elevation of Privilege Vulnerability |
Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network. |
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network. |
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector |
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network. |
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. |
Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. |
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. |
1Microsoft 2Azure Core Shared Client Library Azure Sdk For PythonJun 17, 2026 Jan 13, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJul 30, 2026 Jan 13, 2026 N/A· v4 6.4 MEDIUM· v3 N/A· v2 Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure B...Show more |
1Microsoft 1Azure Connected Machine Agent Jun 17, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. |
1Microsoft 3Windows 11 24h2 Windows 11 25h2Windows Server 2025Jul 30, 2026 Jan 13, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. |
1Microsoft 1Windows Software Development Kit Jun 17, 2026 Jan 13, 2026 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. |
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally. |