Microsoft
microsoft
15,699 CVEs • 1,070 products
Products (1,070)
Click to collapseToggle
Products (1,070)
Click to collapse
CVEs (15,699)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Azure Sql Managed Instance Aug 12, 2026 Aug 7, 2026 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. |
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. |
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. |
1Microsoft 1Entra Provisioning Service Aug 7, 2026 Aug 7, 2026 N/A· v4 9.9 CRITICAL· v3 N/A· v2 '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. |
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. |
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. |
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. |
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. |
1Microsoft 1Application Insights Profiler Aug 17, 2026 Aug 7, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. |
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. |
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. |
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. |