Microsoft
microsoft
15,699 CVEs • 1,070 products
Products (1,070)
Click to collapseToggle
Products (1,070)
Click to collapse
CVEs (15,699)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. |
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. |
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. |
1Microsoft 5365 Apps ExcelOffice 2019+2 moreAug 9, 2026 Aug 4, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. |
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. |
Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. |
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. |
1Microsoft 1Azure App Service For Linux Aug 6, 2026 Jul 24, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. |
1Microsoft 1Purview Data Governance Jul 29, 2026 Jul 24, 2026 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. |
1Microsoft 1Azure Kubernetes Service Jul 29, 2026 Jul 24, 2026 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. |
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. |
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. |
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. |
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. |
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. |
1Microsoft 1Azure Red Hat Openshift Aug 7, 2026 Jul 24, 2026 N/A· v4 9.9 CRITICAL· v3 N/A· v2 Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. |