Microsoft
microsoft
16,014 CVEs • 1,072 products
Products (1,072)
Click to collapseToggle
Products (1,072)
Click to collapse
CVEs (16,014)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability |
Azure OpenAI Elevation of Privilege Vulnerability |
1Microsoft 2Exchange Server Exchange Server Subscription EditionJun 17, 2026 Aug 6, 2025 N/A· v4 8.0 HIGH· v3 N/A· v2 On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hyb...Show more |
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Micro...Show more |
Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network. |
Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. |
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. |
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Jul 8, 2025 N/A· v4 3.5 LOW· v3 N/A· v2 External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network. |
Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally. |
1Microsoft 7Windows Server 2008 Windows Server 2012Windows Server 2016+4 moreJun 17, 2026 Jul 8, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Jul 8, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Jul 8, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally. |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Jul 8, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network. |