← Back

Microsoft

microsoft

16,308 CVEs • 1,074 products

Products (1,074)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
365 Apps
365_apps
Edge
edge
Windows Xp
windows_xp
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Office 2021
office_2021
Office 2024
office_2024
Office 2019
office_2019
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Office 2016
office_2016
.net
Dynamics 365
dynamics_365
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Asp.net Core
asp.net_core
Access
access

CVEs (16,308)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
6Windows Server 2008
Windows Server 2012Windows Server 2016+3 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Windows Netlogon Elevation of Privilege Vulnerability
1Microsoft
1Azure Monitor Agent
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Azure Monitor Agent Elevation of Privilege Vulnerability
1Microsoft
1Windows Server 2022 23h2
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
1Microsoft
4Windows Server 2012
Windows Server 2016Windows Server 2019+1 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Kernel Elevation of Privilege Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Windows Hyper-V Remote Code Execution Vulnerability
1Microsoft
10Windows 10 1809
Windows 10 21h2Windows 10 22h2+7 more
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Windows Hyper-V Security Feature Bypass Vulnerability
1Microsoft
1Nugetgallery
Jun 17, 2026
Oct 1, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code...Show more
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser.Show less
1Microsoft
1Power Platform Terraform Provider
Jun 17, 2026
Sep 25, 2024
8.8 HIGH· v4
7.5 HIGH· v3
N/A· v2
Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform Provider where sensitive information, specif...Show more
Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform Provider where sensitive information, specifically the `client_secret` used in the service principal authentication, may be exposed in logs. This exposure occurs due to an error in the logging code that causes the `client_secret` to not be properly masked when logs are persisted or viewed. Users should upgrade to version 3.0.0 to receive a patched version of the provider that removes all logging of sensitive content. Users who have used this provider with the affected versions should take the following additional steps to mitigate the risk: Immediately rotate the `client_secret` for any service principal that has been configured using this Terraform provider. This will invalidate any potentially exposed secrets. Those who have set the `TF_LOG_PATH` environment variable or configured Terraform to persist logs to a file or an external system, consider disabling this until they have updated to a fixed version of the provider. Those who have existing logs that may contain the `client_secret` should remove or sanitize these logs to prevent unauthorized access. This includes logs on disk, in monitoring systems, or in logging services.Show less
1Microsoft
1Edge Chromium
Aug 10, 2026
Sep 19, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
1Microsoft
1Edge Chromium
Aug 10, 2026
Sep 19, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
1Microsoft
1Edge Chromium
Aug 10, 2026
Sep 19, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1Microsoft
4365 Apps
OfficeOffice Long Term Servicing Channel+1 more
Aug 10, 2026
Sep 19, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Microsoft Office Visio Remote Code Execution Vulnerability
1Microsoft
2Windows 11 22h2
Windows 11 23h2
Jun 17, 2026
Sep 17, 2024
N/A· v4
5.6 MEDIUM· v3
N/A· v2
Windows Kernel Information Disclosure Vulnerability
1Microsoft
1Dynamics 365 Business Central
Aug 10, 2026
Sep 17, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
1Microsoft
1Groupme
Aug 10, 2026
Sep 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.
1Microsoft
1High Definition Audio Bus Driver
Jun 17, 2026
Sep 12, 2024
N/A· v4
5.0 MEDIUM· v3
N/A· v2
A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IR...Show more
A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a local denial-of-service. An attacker can execute malicious script/application to trigger this vulnerability.Show less
1Microsoft
1Edge
Aug 10, 2026
Sep 12, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability