← Back

Microsoft

microsoft

15,661 CVEs • 1,070 products

Products (1,070)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Office 2021
office_2021
Office 2024
office_2024
Office 2019
office_2019
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
.net
Dynamics 365
dynamics_365
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Office 2016
office_2016
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Access
access

CVEs (15,661)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Exchange Online
Aug 24, 2026
Aug 20, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
1Microsoft
1Azure Managed Instance For Apache Cassandra
Aug 25, 2026
Aug 20, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
1Microsoft
1Fabric
Sep 4, 2026
Aug 20, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
1Microsoft
1Azure Data Factory
Aug 24, 2026
Aug 20, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
1Microsoft
1Remote Help
Aug 26, 2026
Aug 20, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
1Microsoft
1Remote Help
Aug 26, 2026
Aug 20, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
1Microsoft
1Windows App
Aug 27, 2026
Aug 19, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Sep 8, 2026
Aug 19, 2026
N/A· v4
7.0 HIGH· v3
N/A· v2
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
1Microsoft
1Copilot
Sep 10, 2026
Aug 18, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
1Microsoft
1Malware Protection Engine
Sep 3, 2026
Aug 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
1Microsoft
1Powershell
Aug 18, 2026
Aug 14, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
1Microsoft
1Edge Chromium
Aug 18, 2026
Aug 14, 2026
N/A· v4
8.3 HIGH· v3
N/A· v2
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
1Microsoft
1Edge Chromium
Aug 17, 2026
Aug 11, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
1Microsoft
1Onedrive
Aug 17, 2026
Aug 11, 2026
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
1Microsoft
1Windows 11 26h1
Aug 14, 2026
Aug 11, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
1Microsoft
4Windows 10 1809
Windows Server 2019Windows Server 2022+1 more
Aug 20, 2026
Aug 11, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
1Microsoft
1Sharepoint Server
Aug 13, 2026
Aug 11, 2026
N/A· v4
8.7 HIGH· v3
N/A· v2
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
1Microsoft
4.net
.net FrameworkVisual Studio 2022+1 more
Aug 17, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
1Microsoft
3Windows 11 24h2
Windows 11 25h2Windows 11 26h1
Aug 14, 2026
Aug 11, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
1Microsoft
13Windows 10 1607
Windows 10 1809Windows 10 21h2+10 more
Aug 16, 2026
Aug 11, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.