| CVE-2026-58276 | 7.5 | high | microsoft / edge chromium | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 64d ago |
| CVE-2026-57992 | 7.5 | high | microsoft / edge chromium | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 64d ago |
| CVE-2026-57986 | 7.5 | high | microsoft / edge chromium | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 64d ago |
| CVE-2026-57984 | 7.5 | high | microsoft / edge chromium | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 64d ago |
| CVE-2026-57975 | 7.5 | high | microsoft / edge chromium | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unautho | 64d ago |
| CVE-2025-66389 | 7.5 | high | microsoft / github copilot | GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-h | 75d ago |
| CVE-2026-47633 | 7.5 | high | microsoft / cost management | Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an un | 79d ago |
| CVE-2026-49160 | 7.5 | high | microsoft / windows 10 1607 | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. | 88d ago |
| CVE-2026-48563 | 7.5 | high | microsoft / windows 10 1809 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-47654 | 7.5 | high | microsoft / windows server 2016 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-45639 | 7.5 | high | microsoft / remote desktop client | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 88d ago |
| CVE-2026-45591 | 7.5 | high | microsoft / asp.net core | Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 88d ago |
| CVE-2026-45583 | 7.5 | high | microsoft / exchange server | Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized atta | 88d ago |
| CVE-2026-44801 | 7.5 | high | microsoft / remote desktop client | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-44799 | 7.5 | high | microsoft / remote desktop client | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 88d ago |
| CVE-2026-42993 | 7.5 | high | microsoft / windows 10 21h2 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 88d ago |
| CVE-2026-42992 | 7.5 | high | microsoft / windows app | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 88d ago |
| CVE-2026-42913 | 7.5 | high | microsoft / remote desktop client | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Clie | 88d ago |
| CVE-2026-42909 | 7.5 | high | microsoft / remote desktop client | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Clie | 88d ago |
| CVE-2026-42908 | 7.5 | high | microsoft / windows app | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 88d ago |
| CVE-2026-40376 | 7.5 | high | microsoft / visual studio code | Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a netwo | 88d ago |
| CVE-2026-23663 | 7.5 | high | microsoft / global secure access | Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a netwo | 106d ago |
| CVE-2026-42899 | 7.5 | high | microsoft / .net | Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny ser | 116d ago |
| CVE-2026-40406 | 7.5 | high | microsoft / windows 10 1607 | Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network. | 116d ago |
| CVE-2026-40405 | 7.5 | high | microsoft / windows 11 24h2 | Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | 116d ago |
| CVE-2026-35424 | 7.5 | high | microsoft / windows 10 1607 | Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unaut | 116d ago |
| CVE-2026-32161 | 7.5 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi | 116d ago |
| CVE-2026-25667 | 7.5 | high | microsoft / .net | ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to ca | 170d ago |
| CVE-2026-58612 | 7.4 | high | microsoft / powershell | Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose inform | 25d ago |
| CVE-2026-66321 | 7.4 | high | microsoft / edge chromium | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unautho | 33d ago |
| CVE-2026-65802 | 7.4 | high | microsoft / edge chromium | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose in | 33d ago |
| CVE-2026-57990 | 7.4 | high | microsoft / edge chromium | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized atta | 41d ago |
| CVE-2026-57989 | 7.4 | high | microsoft / edge chromium | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information | 41d ago |
| CVE-2026-54127 | 7.4 | high | microsoft / windows 11 24h2 | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-57993 | 7.4 | high | microsoft / edge chromium | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform s | 64d ago |
| CVE-2026-57991 | 7.4 | high | microsoft / edge chromium | Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauth | 64d ago |
| CVE-2026-42893 | 7.4 | high | microsoft / outlook | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unau | 116d ago |
| CVE-2026-41107 | 7.4 | high | microsoft / edge chromium | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclo | 116d ago |
| CVE-2026-40414 | 7.4 | high | microsoft / windows 10 1607 | Windows TCP/IP Denial of Service Vulnerability | 116d ago |
| CVE-2026-40413 | 7.4 | high | microsoft / windows 10 1607 | Windows TCP/IP Denial of Service Vulnerability | 116d ago |
| CVE-2026-70355 | 7.3 | high | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 25d ago |
| CVE-2026-68821 | 7.3 | high | microsoft / app installer | Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges local | 25d ago |
| CVE-2026-64900 | 7.3 | high | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 25d ago |
| CVE-2026-62914 | 7.3 | high | microsoft / exchange server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server | 25d ago |
| CVE-2026-59119 | 7.3 | high | microsoft / powershell | Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-55126 | 7.3 | high | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 53d ago |
| CVE-2026-55034 | 7.3 | high | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 53d ago |
| CVE-2026-55021 | 7.3 | high | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 53d ago |
| CVE-2026-50482 | 7.3 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 53d ago |
| CVE-2026-58640 | 7.3 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 53d ago |
| CVE-2026-50364 | 7.3 | high | microsoft / windows 10 21h2 | Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attac | 53d ago |
| CVE-2026-49790 | 7.3 | high | microsoft / windows 10 1607 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 53d ago |
| CVE-2026-49789 | 7.3 | high | microsoft / windows 10 1607 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-47634 | 7.3 | high | microsoft / sharepoint server | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Of | 88d ago |
| CVE-2026-45481 | 7.3 | high | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 88d ago |
| CVE-2026-35433 | 7.3 | high | microsoft / .net framework | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-32177 | 7.3 | high | microsoft / visual studio 2022 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-62910 | 7.2 | high | microsoft / exchange server | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized | 25d ago |
| CVE-2026-47299 | 7.2 | high | microsoft / azure monitor agent | Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows | 25d ago |
| CVE-2026-58298 | 7.2 | high | microsoft / edge chromium | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-b | 64d ago |