Search: "microsoft"

7882 CVEs found

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: 2026-03-10
Products: 13
Vendors:
microsoft

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: 2026-03-10
Products: 14
Vendors:
microsoft

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: 2026-03-10
Products: 13
Vendors:
microsoft

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

Published: 2026-03-10
Products: 13
Vendors:
microsoft

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: 2026-03-10
Products: 13
Vendors:
microsoft

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

Published: 2026-03-10
Products: 14
Vendors:
microsoft

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Published: 2026-03-10
Products: 2
Vendors:
microsoft

Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

Published: 2026-03-10
Products: 1
Vendors:
microsoft

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Published: 2026-03-10
Products: 2
Vendors:
microsoft
CVE-2026-26123
5.5 MEDIUM

Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.

Published: 2026-03-10
Products: 2
Vendors:
microsoft

In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file during the installation process, which may result in unintended elevation of privil...

Published: 2026-03-11
Products: 0
CVE-2026-31957
10.0 CRITICAL

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant domain in himmelblau.conf, authentica...

Published: 2026-03-11
Products: 1
Vendors:
himmelblau-idm

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelblaud-tasks daemon, running as root, writes Kerberos cache files under /tmp/krb5cc_...

Published: 2026-03-11
Products: 2
Vendors:
himmelblau-idm
CVE-2026-0385
5.0 MEDIUM

Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

Published: 2026-03-16
Products: 1
Vendors:
microsoft
CVE-2026-2559
5.3 MEDIUM

The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `handle_office365_oauth_redirect()` function in all versions up to, and i...

Published: 2026-03-18
Products: 0

Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; thi...

Published: 2026-03-18
Products: 0

ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrec...

Published: 2026-03-19
Products: 2
Vendors:
microsoft
CVE-2026-26120
6.5 MEDIUM

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.

Published: 2026-03-19
Products: 1
Vendors:
microsoft
CVE-2026-26136
6.5 MEDIUM

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Published: 2026-03-19
Products: 1
Vendors:
microsoft
CVE-2026-26137
9.9 CRITICAL

Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.

Published: 2026-03-19
Products: 1
Vendors:
microsoft