← Back

Microsoft

microsoft

14,960 CVEs • 1,050 products

Products (1,050)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2024
office_2024
Office 2021
office_2021
Dynamics 365
dynamics_365
Office 2019
office_2019
Microsoft 365
microsoft_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Office 2016
office_2016

CVEs (14,960)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
10Windows 10 1809
Windows 10 21h2Windows 10 22h2+7 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Windows Hyper-V Security Feature Bypass Vulnerability
1Microsoft
1Nugetgallery
Jun 17, 2026
Oct 1, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code...Show more
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser.Show less
1Microsoft
1Power Platform Terraform Provider
Jun 17, 2026
Sep 25, 2024
8.8 HIGH· v4
7.5 HIGH· v3
N/A· v2
Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform Provider where sensitive information, specif...Show more
Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform Provider where sensitive information, specifically the `client_secret` used in the service principal authentication, may be exposed in logs. This exposure occurs due to an error in the logging code that causes the `client_secret` to not be properly masked when logs are persisted or viewed. Users should upgrade to version 3.0.0 to receive a patched version of the provider that removes all logging of sensitive content. Users who have used this provider with the affected versions should take the following additional steps to mitigate the risk: Immediately rotate the `client_secret` for any service principal that has been configured using this Terraform provider. This will invalidate any potentially exposed secrets. Those who have set the `TF_LOG_PATH` environment variable or configured Terraform to persist logs to a file or an external system, consider disabling this until they have updated to a fixed version of the provider. Those who have existing logs that may contain the `client_secret` should remove or sanitize these logs to prevent unauthorized access. This includes logs on disk, in monitoring systems, or in logging services.Show less
1Microsoft
1Edge Chromium
Jun 17, 2026
Sep 19, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
1Microsoft
1Edge Chromium
Jun 17, 2026
Sep 19, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
1Microsoft
1Edge Chromium
Jun 17, 2026
Sep 19, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1Microsoft
4365 Apps
OfficeOffice Long Term Servicing Channel+1 more
Jun 17, 2026
Sep 19, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Office Visio Remote Code Execution Vulnerability
1Microsoft
2Windows 11 22h2
Windows 11 23h2
Jun 17, 2026
Sep 17, 2024
N/A· v4
5.6 MEDIUM· v3
N/A· v2
Windows Kernel Information Disclosure Vulnerability
1Microsoft
1Dynamics 365 Business Central
Jun 17, 2026
Sep 17, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
1Microsoft
1Groupme
Jun 17, 2026
Sep 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.
1Microsoft
1High Definition Audio Bus Driver
Jun 17, 2026
Sep 12, 2024
N/A· v4
5.0 MEDIUM· v3
N/A· v2
A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IR...Show more
A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a local denial-of-service. An attacker can execute malicious script/application to trigger this vulnerability.Show less
1Microsoft
1Edge
Jun 17, 2026
Sep 12, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
1Microsoft
3Windows 11 22h2
Windows 11 23h2Windows Server 2022 23h2
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Windows libarchive Remote Code Execution Vulnerability
1Microsoft
1Autoupdate
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
1Microsoft
1Windows 10 1507
Jun 17, 2026
Sep 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means...Show more
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.Show less
1Microsoft
8Windows 10 1507
Windows 10 1607Windows 10 1809+5 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Windows Mark of the Web Security Feature Bypass Vulnerability
1Microsoft
1Outlook
Jun 17, 2026
Sep 10, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Microsoft Outlook for iOS Information Disclosure Vulnerability
1Microsoft
1Power Automate
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.5 HIGH· v3
N/A· v2
Microsoft Power Automate Desktop Remote Code Execution Vulnerability
1Microsoft
1Dynamics 365
Jun 17, 2026
Sep 10, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
1Microsoft
1Windows Server 2008
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Microsoft Windows Admin Center Information Disclosure Vulnerability