| CVE-2026-45476 | 8.2 | high | microsoft / azure network adapter | Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-44822 | 8.2 | high | microsoft / 365 apps | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a networ | 88d ago |
| CVE-2026-33833 | 8.2 | high | microsoft / azure machine learning | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machin | 116d ago |
| CVE-2026-71331 | 8.1 | high | microsoft / windows 10 1809 | Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execu | 25d ago |
| CVE-2026-70340 | 8.1 | high | microsoft / azure cyclecloud | Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | 25d ago |
| CVE-2026-66802 | 8.1 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Heal | 25d ago |
| CVE-2026-65796 | 8.1 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a | 25d ago |
| CVE-2026-65789 | 8.1 | high | microsoft / windows 10 1607 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-65679 | 8.1 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a | 25d ago |
| CVE-2026-63520 | 8.1 | high | microsoft / sharepoint server | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a ne | 25d ago |
| CVE-2026-62889 | 8.1 | high | microsoft / windows 10 1607 | Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code ove | 25d ago |
| CVE-2026-62820 | 8.1 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows | 25d ago |
| CVE-2026-62819 | 8.1 | high | microsoft / windows 10 1607 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized | 25d ago |
| CVE-2026-62792 | 8.1 | high | microsoft / windows 10 1607 | Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-62781 | 8.1 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-62778 | 8.1 | high | microsoft / windows 10 1607 | Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. | 25d ago |
| CVE-2026-66318 | 8.1 | high | microsoft / edge chromium | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information | 33d ago |
| CVE-2026-47304 | 8.1 | high | microsoft / .net framework | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feat | 53d ago |
| CVE-2026-58617 | 8.1 | high | microsoft / 365 copilot | Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges ove | 53d ago |
| CVE-2026-56186 | 8.1 | high | microsoft / windows 10 1607 | Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. | 53d ago |
| CVE-2026-50686 | 8.1 | high | microsoft / windows 10 1607 | Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to ex | 53d ago |
| CVE-2026-50487 | 8.1 | high | microsoft / windows 11 24h2 | Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network. | 53d ago |
| CVE-2026-50460 | 8.1 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50439 | 8.1 | high | microsoft / windows 10 1607 | Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a n | 53d ago |
| CVE-2026-58595 | 8.1 | high | microsoft / bing search | Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker | 53d ago |
| CVE-2026-56169 | 8.1 | high | microsoft / windows admin center | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network | 53d ago |
| CVE-2026-54995 | 8.1 | high | microsoft / windows 10 1607 | Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code ove | 53d ago |
| CVE-2026-50694 | 8.1 | high | microsoft / windows 10 1607 | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code | 53d ago |
| CVE-2026-49164 | 8.1 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code ove | 53d ago |
| CVE-2026-42900 | 8.1 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store a | 53d ago |
| CVE-2026-58293 | 8.1 | high | microsoft / edge chromium | External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execut | 64d ago |
| CVE-2026-58286 | 8.1 | high | microsoft / edge chromium | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ove | 64d ago |
| CVE-2026-58283 | 8.1 | high | microsoft / edge chromium | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unautho | 64d ago |
| CVE-2026-58282 | 8.1 | high | microsoft / edge chromium | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ove | 64d ago |
| CVE-2026-47631 | 8.1 | high | microsoft / exchange server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server | 88d ago |
| CVE-2026-45635 | 8.1 | high | microsoft / windows 10 1607 | Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unau | 88d ago |
| CVE-2026-45599 | 8.1 | high | microsoft / windows 10 1607 | Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a networ | 88d ago |
| CVE-2026-45503 | 8.1 | high | microsoft / exchange server | Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a n | 88d ago |
| CVE-2026-42987 | 8.1 | high | microsoft / windows server 2012 | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-42981 | 8.1 | high | microsoft / windows 11 23h2 | Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute c | 88d ago |
| CVE-2026-42974 | 8.1 | high | microsoft / windows 11 23h2 | Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over | 88d ago |
| CVE-2026-42835 | 8.1 | high | microsoft / teams | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Te | 88d ago |
| CVE-2026-45584 | 8.1 | high | microsoft / malware protection engine | Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. | 108d ago |
| CVE-2026-42897exploited | 8.1 | high | microsoft / exchange server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server | 114d ago |
| CVE-2026-40415 | 8.1 | high | microsoft / windows 10 1809 | Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | 116d ago |
| CVE-2026-62911 | 8 | high | microsoft / exchange server | Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate priv | 25d ago |
| CVE-2026-57105 | 8 | high | microsoft / sharepoint server | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoin | 25d ago |
| CVE-2026-35425 | 8 | high | microsoft / azure api management | Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a networ | 44d ago |
| CVE-2026-50683 | 8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adja | 53d ago |
| CVE-2026-50502 | 8 | high | microsoft / windows 10 1607 | Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execu | 53d ago |
| CVE-2026-50365 | 8 | high | microsoft / windows 10 1607 | Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent | 53d ago |
| CVE-2026-58647 | 8 | high | microsoft / power bi report server | Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authori | 53d ago |
| CVE-2026-49169 | 8 | high | microsoft / windows server 2025 | Use after free in DNS Server allows an authorized attacker to execute code over a network. | 53d ago |
| CVE-2026-42975 | 8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over a | 53d ago |
| CVE-2026-40400 | 8 | high | microsoft / windows 10 1607 | Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. | 53d ago |
| CVE-2026-47298 | 8 | high | microsoft / sharepoint server | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network | 88d ago |
| CVE-2026-45644 | 8 | high | microsoft / live share canvas | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canva | 88d ago |
| CVE-2026-47294 | 8 | high | microsoft / sharepoint server | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office Sha | 96d ago |
| CVE-2026-40368 | 8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 116d ago |
| CVE-2026-34332 | 8 | high | microsoft / windows server 2025 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. | 116d ago |