Search: "microsoft"

7881 CVEs found

CVE-2026-26149
9.0 CRITICAL

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.

Published: 2026-04-14
Products: 0
CVE-2026-26155
6.5 MEDIUM

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

Published: 2026-04-14
Products: 23
Vendors:
microsoft

Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

Published: 2026-04-14
Products: 23
Vendors:
microsoft

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Published: 2026-04-14
Products: 10
Vendors:
microsoft

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Published: 2026-04-14
Products: 25
Vendors:
microsoft

Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.

Published: 2026-04-14
Products: 25
Vendors:
microsoft

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

Published: 2026-04-14
Products: 23
Vendors:
microsoft

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Published: 2026-04-14
Products: 16
Vendors:
microsoft
CVE-2026-32181
5.5 MEDIUM

Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.

Published: 2026-04-14
Products: 17
Vendors:
microsoft

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally.

Published: 2026-04-14
Products: 0

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Published: 2026-04-14
Products: 13
Vendors:
microsoft

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: 2026-04-14
Products: 13
Vendors:
microsoft

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Published: 2026-04-14
Products: 12
Vendors:
microsoft

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: 2026-04-14
Products: 13
Vendors:
microsoft

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: 2026-04-14
Products: 13
Vendors:
microsoft

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Published: 2026-04-14
Products: 13
Vendors:
microsoft

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

Published: 2026-04-14
Products: 9
Vendors:
microsoft
CVE-2026-32201
6.5 MEDIUM

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Published: 2026-04-14
Products: 3
Vendors:
microsoft

Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Published: 2026-04-14
Products: 7
Vendors:
microsoft

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

Published: 2026-04-14
Products: 7
Vendors:
microsoft