Microsoft
microsoft
14,951 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,951)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 May 12, 2026 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally. |
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. |
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally. |
1Microsoft 4.net .net FrameworkVisual Studio 2022+1 moreJul 15, 2026 May 12, 2026 N/A· v4 7.3 HIGH· v3 N/A· v2 Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. |
1Microsoft 3.net Visual Studio 2022Visual Studio 2026Jun 18, 2026 May 12, 2026 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a...Show more |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 May 12, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 May 12, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJun 17, 2026 May 12, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. |
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. |
1Microsoft 1Azure Monitor Action Group Notification System Jun 17, 2026 May 7, 2026 N/A· v4 8.1 HIGH· v3 N/A· v2 Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. |
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. |
Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network. |
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network. |
1Microsoft 1Azure Managed Instance For Apache Cassandra Jun 17, 2026 May 7, 2026 N/A· v4 9.0 CRITICAL· v3 N/A· v2 Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. |
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. |
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. |
1Microsoft 1Azure Managed Instance For Apache Cassandra Jun 17, 2026 May 7, 2026 N/A· v4 9.9 CRITICAL· v3 N/A· v2 Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. |
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. |