| CVE-2026-54118 | 9.8 | critical | microsoft / sql server 2016 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-54117 | 9.8 | critical | microsoft / sql server 2016 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-50522exploited | 9.8 | critical | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code o | 53d ago |
| CVE-2026-49172 | 9.8 | critical | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-42990 | 9.8 | critical | microsoft / windows 10 1607 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a networ | 53d ago |
| CVE-2026-54130 | 9.8 | critical | microsoft / 365 copilot | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose informati | 79d ago |
| CVE-2026-47643 | 9.8 | critical | microsoft / azure stack edge | External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a n | 88d ago |
| CVE-2026-47291 | 9.8 | critical | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-45657 | 9.8 | critical | microsoft / windows 11 23h2 | Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-44815 | 9.8 | critical | microsoft / windows 10 1607 | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-26142 | 9.8 | critical | microsoft / nuance powerscribe 360 | Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a net | 88d ago |
| CVE-2026-41096 | 9.8 | critical | microsoft / windows 11 23h2 | Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network | 116d ago |
| CVE-2026-41089 | 9.8 | critical | microsoft / windows server 2012 | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. | 116d ago |
| CVE-2026-32194 | 9.8 | critical | microsoft / bing images | Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allow | 170d ago |
| CVE-2026-32191 | 9.8 | critical | microsoft / bing images | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Image | 170d ago |
| CVE-2026-69400 | 9.6 | critical | microsoft / azure logic apps | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unaut | 16d ago |
| CVE-2026-70332 | 9.6 | critical | microsoft / sharepoint online | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 30d ago |
| CVE-2026-62896 | 9.6 | critical | microsoft / teams | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | 30d ago |
| CVE-2026-56161 | 9.6 | critical | microsoft / azure logic apps | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | 30d ago |
| CVE-2026-50380 | 9.6 | critical | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-55008 | 9.6 | critical | microsoft / exchange server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server | 53d ago |
| CVE-2026-48561 | 9.6 | critical | microsoft / 365 copilot | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edg | 53d ago |
| CVE-2026-48582 | 9.6 | critical | microsoft / exchange online | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a netw | 78d ago |
| CVE-2026-47281 | 9.6 | critical | microsoft / visual studio code | Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 88d ago |
| CVE-2026-42904 | 9.6 | critical | microsoft / windows 10 21h2 | Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacen | 88d ago |
| CVE-2026-41615 | 9.6 | critical | microsoft / authenticator | Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attac | 114d ago |
| CVE-2026-50516 | 9.4 | critical | microsoft / azure kubernetes service | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker | 25d ago |
| CVE-2026-62834 | 9.3 | critical | microsoft / azure data factory | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate | 16d ago |
| CVE-2026-70306 | 9.3 | critical | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 25d ago |
| CVE-2026-59118 | 9.3 | critical | microsoft / power apps | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | 30d ago |
| CVE-2026-62835 | 9.3 | critical | microsoft / azure portal | Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. | 43d ago |
| CVE-2026-49798 | 9.3 | critical | microsoft / windows 10 1607 | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-47646 | 9.3 | critical | microsoft / dynamics 365 customer voice | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voic | 59d ago |
| CVE-2026-41106 | 9.3 | critical | microsoft / 365 copilot | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate pri | 65d ago |
| CVE-2026-41090 | 9.3 | critical | microsoft / 365 copilot | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an | 106d ago |
| CVE-2026-40402 | 9.3 | critical | microsoft / windows 11 23h2 | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-40379 | 9.3 | critical | microsoft / entra id | Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to pe | 116d ago |
| CVE-2026-66309 | 9.1 | critical | microsoft / azure sql database | Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | 16d ago |
| CVE-2026-68823 | 9.1 | critical | microsoft / azure confidential ledger | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code ov | 30d ago |
| CVE-2026-56160 | 9.1 | critical | microsoft / azure red hat openshift | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a | 44d ago |
| CVE-2026-55040exploited | 9.1 | critical | microsoft / sharepoint server | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature ov | 53d ago |
| CVE-2025-62821 | 9.1 | critical | microsoft / heif image extension | Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can retu | 78d ago |
| CVE-2026-45602 | 9.1 | critical | microsoft / windows 10 1607 | No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. | 88d ago |
| CVE-2026-48579 | 9.1 | critical | microsoft / exchange online | Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a | 93d ago |
| CVE-2026-33843 | 9.1 | critical | microsoft / entra id | Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unautho | 106d ago |
| CVE-2026-42833 | 9.1 | critical | microsoft / dynamics 365 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an author | 116d ago |
| CVE-2026-41103 | 9.1 | critical | microsoft / confluence saml sso | Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an u | 116d ago |
| CVE-2026-33117 | 9.1 | critical | microsoft / azure sdk for java | The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verificatio | 116d ago |
| CVE-2026-58289 | 9 | critical | microsoft / edge chromium | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unautho | 64d ago |