Microsoft
microsoft
14,981 CVEs • 1,052 products
Products (1,052)
Click to collapseToggle
Products (1,052)
Click to collapse
CVEs (14,981)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Windows Server 2012 Windows Server 2016Jun 17, 2026 Aug 15, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles multi-factor authentication requests, aka "AD FS Security Feature Bypass Vulnerability." This affects Wi...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreJun 17, 2026 Aug 15, 2018 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior, aka "Windows Installer Elevation of Pri...Show more |
A remote code execution vulnerability exists when Internet Explorer improperly validates hyperlinks before loading executable libraries, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet...Show more |
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft E...Show more |
A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL...Show more |
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft...Show more |
1Microsoft 2Windows 10 Windows Server 2016Jun 17, 2026 Aug 15, 2018 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscreen, aka "Microsoft Cortana Elevation of Privilege Vulnerability." This affects Windows Server 2016, W...Show more |
1Microsoft 2Windows 10 Windows Server 2016Jun 17, 2026 Aug 15, 2018 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vuln...Show more |
1Microsoft 2Windows 10 Windows Server 2016Jun 17, 2026 Aug 15, 2018 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vuln...Show more |
1Microsoft 4Visual Studio 2015 Visual Studio 2017Windows 10+1 moreNov 21, 2024 Aug 15, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability." This affec...Show more |
1Microsoft 5.net Core .net Framework.net Framework Developer Pack+2 moreJun 17, 2026 Jul 11, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7....Show more |
1Microsoft 2Powershell Powershell Editor ServicesJun 17, 2026 Jul 11, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension. |
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD...Show more |
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from...Show more |
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from...Show more |
1Microsoft 1Sharepoint Enterprise Server Jun 17, 2026 Jul 11, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privileg...Show more |
1Microsoft 1Research Javascript Cryptography Library Jun 17, 2026 Jul 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka "MSR JavaScript Cryptography Library Security Feature Bypass Vulnerability."...Show more |
1Microsoft 6Windows 10 Windows 7Windows 8.1+3 moreJun 17, 2026 Jul 11, 2018 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 An elevation of privilege vulnerability exists when Windows fails a check, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Wi...Show more |
1Microsoft 5Windows 10 Windows 8.1Windows Rt 8.1+2 moreJun 17, 2026 Jul 11, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows...Show more |
A remote code execution vulnerability exists when Microsoft Access fails to properly handle objects in memory, aka "Microsoft Access Remote Code Execution Vulnerability." This affects Microsoft Access, Microsoft Office. |