| CVE-2026-34329 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adja | 116d ago |
| CVE-2026-33112 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 116d ago |
| CVE-2026-33110 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 116d ago |
| CVE-2026-62836 | 8.7 | high | microsoft / azure sql managed instance | Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauth | 30d ago |
| CVE-2026-57983 | 8.7 | high | microsoft / edge chromium | Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security fea | 64d ago |
| CVE-2026-69558 | 8.6 | high | microsoft / partner center | Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to di | 16d ago |
| CVE-2026-69519 | 8.6 | high | microsoft / azure stack hci | Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a | 16d ago |
| CVE-2026-66800 | 8.6 | high | microsoft / azure data factory | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information o | 16d ago |
| CVE-2026-26139 | 8.6 | high | microsoft / purview | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over | 170d ago |
| CVE-2026-26138 | 8.6 | high | microsoft / purview | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over | 170d ago |
| CVE-2026-23659 | 8.6 | high | microsoft / azure data factory | Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker t | 170d ago |
| CVE-2026-23658 | 8.6 | high | microsoft / azure devops | Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a | 170d ago |
| CVE-2026-69543 | 8.5 | high | microsoft / azure virtual machines | Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges o | 16d ago |
| CVE-2026-69419 | 8.5 | high | microsoft / azure data manager for energy | Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over | 16d ago |
| CVE-2026-56167 | 8.5 | high | microsoft / azure ai search | Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a n | 44d ago |
| CVE-2026-50340 | 8.5 | high | microsoft / windows 11 24h2 | Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. | 53d ago |
| CVE-2026-70130 | 8.4 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-55045 | 8.4 | high | microsoft / 365 apps | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | 53d ago |
| CVE-2026-54128 | 8.4 | high | microsoft / windows 10 1607 | Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. | 53d ago |
| CVE-2026-54992 | 8.4 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute cod | 53d ago |
| CVE-2026-54122 | 8.4 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | 53d ago |
| CVE-2026-50520 | 8.4 | high | microsoft / visual studio code | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows a | 53d ago |
| CVE-2026-49184 | 8.4 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 53d ago |
| CVE-2026-47635 | 8.4 | high | microsoft / office 2024 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-45641 | 8.4 | high | microsoft / windows 10 21h2 | Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker t | 88d ago |
| CVE-2026-45607 | 8.4 | high | microsoft / windows 10 1607 | Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-45482 | 8.4 | high | microsoft / visual studio code | Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio | 88d ago |
| CVE-2026-45474 | 8.4 | high | microsoft / 365 apps | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-45472 | 8.4 | high | microsoft / 365 apps | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-45463 | 8.4 | high | microsoft / 365 apps | Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally | 88d ago |
| CVE-2026-45461 | 8.4 | high | microsoft / 365 apps | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-45458 | 8.4 | high | microsoft / 365 apps | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-45456 | 8.4 | high | microsoft / 365 apps | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker | 88d ago |
| CVE-2026-44810 | 8.4 | high | microsoft / windows 11 23h2 | Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges lo | 88d ago |
| CVE-2026-41098 | 8.4 | high | microsoft / azure stack edge | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an | 88d ago |
| CVE-2026-40367 | 8.4 | high | microsoft / 365 apps | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized atta | 116d ago |
| CVE-2026-40366 | 8.4 | high | microsoft / 365 apps | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized atta | 116d ago |
| CVE-2026-40364 | 8.4 | high | microsoft / 365 apps | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized atta | 116d ago |
| CVE-2026-40363 | 8.4 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 116d ago |
| CVE-2026-40361 | 8.4 | high | microsoft / 365 apps | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 116d ago |
| CVE-2026-40358 | 8.4 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 116d ago |
| CVE-2026-72970 | 8.3 | high | microsoft / edge chromium | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over | 22d ago |
| CVE-2026-56179 | 8.3 | high | microsoft / windows 11 24h2 | Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform sp | 25d ago |
| CVE-2026-56181 | 8.3 | high | microsoft / windows 11 24h2 | Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform sp | 53d ago |
| CVE-2026-58596 | 8.3 | high | microsoft / edge chromium | Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privil | 55d ago |
| CVE-2026-58281 | 8.3 | high | microsoft / edge chromium | Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute co | 56d ago |
| CVE-2026-58295 | 8.3 | high | microsoft / edge chromium | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unautho | 64d ago |
| CVE-2026-58288 | 8.3 | high | microsoft / edge chromium | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 64d ago |
| CVE-2026-58287 | 8.3 | high | microsoft / edge chromium | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 64d ago |
| CVE-2026-58285 | 8.3 | high | microsoft / edge chromium | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unautho | 64d ago |
| CVE-2026-58284 | 8.3 | high | microsoft / edge chromium | Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a n | 64d ago |
| CVE-2026-50521 | 8.3 | high | microsoft / edge chromium | Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | 66d ago |
| CVE-2026-35438 | 8.3 | high | microsoft / windows admin center | Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | 116d ago |
| CVE-2026-69306 | 8.2 | high | microsoft / visual studio code | Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security f | 25d ago |
| CVE-2026-50528 | 8.2 | high | microsoft / .net | Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | 53d ago |
| CVE-2026-50680 | 8.2 | high | microsoft / windows 10 1809 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50429 | 8.2 | high | microsoft / windows 10 1607 | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. | 53d ago |
| CVE-2026-50338 | 8.2 | high | microsoft / azure spring cloud | Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network. | 53d ago |
| CVE-2026-58525 | 8.2 | high | microsoft / edge chromium | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security fe | 59d ago |
| CVE-2026-47652 | 8.2 | high | microsoft / windows 11 23h2 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 88d ago |