Search: "microsoft"

7882 CVEs found

CVE-2026-21265
6.4 MEDIUM

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them ...

Published: 2026-01-13
Products: 23
Vendors:
microsoft

A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, whic...

Published: 2026-01-15
Products: 0

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

Published: 2026-01-16
Products: 1
Vendors:
microsoft

Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

Published: 2026-01-16
Products: 1
Vendors:
microsoft
CVE-2026-23873
9.0 CRITICAL

hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vulnerable to CSV Injection (Formula Injection) through the contest rank export func...

Published: 2026-01-22
Products: 1
Vendors:
hustoj
CVE-2026-21264
9.3 CRITICAL

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.

Published: 2026-01-22
Products: 1
Vendors:
microsoft

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Published: 2026-01-26
Products: 10
Vendors:
microsoft
CVE-2026-24784
6.8 MEDIUM

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, a content editor could...

Published: 2026-01-28
Products: 2
Vendors:
dnnsoftware

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, a module could install with richtext in its descript...

Published: 2026-01-28
Products: 2
Vendors:
dnnsoftware

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, extensions could write...

Published: 2026-01-28
Products: 2
Vendors:
dnnsoftware

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, a module friendly name...

Published: 2026-01-28
Products: 2
Vendors:
dnnsoftware
CVE-2026-24838
9.1 CRITICAL

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include ...

Published: 2026-01-28
Products: 2
Vendors:
dnnsoftware
CVE-2026-0948
6.5 MEDIUM

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Privilege Escalation.This issue affects Microsoft Entra ID SSO Login: from 0.0.0 be...

Published: 2026-02-04
Products: 1
Vendors:
jaseerkinangattil
CVE-2026-0391
6.5 MEDIUM

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.

Published: 2026-02-05
Products: 1
Vendors:
microsoft
CVE-2026-25592
9.9 CRITICAL

Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic K...

Published: 2026-02-06
Products: 0

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Published: 2026-02-10
Products: 17
Vendors:
microsoft

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Published: 2026-02-10
Products: 23
Vendors:
microsoft
CVE-2026-21258
5.5 MEDIUM

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Published: 2026-02-10
Products: 13
Vendors:
microsoft

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.

Published: 2026-02-10
Products: 11
Vendors:
microsoft

Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

Published: 2026-02-10
Products: 13
Vendors:
microsoft