Microsoft
microsoft
14,959 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,959)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Power Automate For Desktop Jun 17, 2026 Jan 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Power Automate Remote Code Execution Vulnerability |
1Microsoft 4365 Apps AccessOffice+1 moreJun 17, 2026 Jan 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Access Remote Code Execution Vulnerability |
1Microsoft 3Visual Studio 2017 Visual Studio 2019Visual Studio 2022Jun 17, 2026 Jan 14, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Visual Studio Remote Code Execution Vulnerability |
1Microsoft 3.net .net FrameworkVisual Studio 2017Jun 17, 2026 Jan 14, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability |
.NET Elevation of Privilege Vulnerability |
1Microsoft 4.net Visual Studio 2017Visual Studio 2019+1 moreJun 17, 2026 Jan 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 .NET and Visual Studio Remote Code Execution Vulnerability |
1Microsoft 3.net PowershellVisual Studio 2022Jun 17, 2026 Jan 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 .NET Remote Code Execution Vulnerability |
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network. |
A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network. |
A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. A malicious application could inject a libr...Show more |
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject...Show more |
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious...Show more |
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a librar...Show more |
A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass. A malicious application could inject a...Show more |
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a...Show more |
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access p...Show more |
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inj...Show more |
1Microsoft 2Windows 11 21h2 Windows Server 2022Jun 17, 2026 Dec 18, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 20...Show more |
1Microsoft 2Windows 11 21h2 Windows Server 2022Jun 17, 2026 Dec 18, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 20...Show more |
Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver. |