| CVE-2026-72984 | 8.8 | high | microsoft / edge chromium | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unautho | 8d ago |
| CVE-2026-70337 | 8.8 | high | microsoft / powershell | Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a networ | 25d ago |
| CVE-2026-70336 | 8.8 | high | microsoft / visual studio code | Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to | 25d ago |
| CVE-2026-70329 | 8.8 | high | microsoft / 365 apps | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a | 25d ago |
| CVE-2026-70326 | 8.8 | high | microsoft / sharepoint server | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privile | 25d ago |
| CVE-2026-70324 | 8.8 | high | microsoft / sharepoint server | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privile | 25d ago |
| CVE-2026-70321 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-69320 | 8.8 | high | microsoft / visual studio code | Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code a | 25d ago |
| CVE-2026-66808 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-66805 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-65815 | 8.8 | high | microsoft / dynamics 365 | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute | 25d ago |
| CVE-2026-65811 | 8.8 | high | microsoft / power bi report server | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | 25d ago |
| CVE-2026-65807 | 8.8 | high | microsoft / 365 apps | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized att | 25d ago |
| CVE-2026-65768 | 8.8 | high | microsoft / teams | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allo | 25d ago |
| CVE-2026-65767 | 8.8 | high | microsoft / teams | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Androi | 25d ago |
| CVE-2026-65665 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-65663 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-65660 | 8.8 | high | microsoft / sharepoint server | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized atta | 25d ago |
| CVE-2026-65658 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-64921 | 8.8 | high | microsoft / sharepoint server | Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to eleva | 25d ago |
| CVE-2026-64901 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-63514 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 25d ago |
| CVE-2026-62913 | 8.8 | high | microsoft / exchange server | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a netwo | 25d ago |
| CVE-2026-62872 | 8.8 | high | microsoft / .net framework | Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | 25d ago |
| CVE-2026-62869 | 8.8 | high | microsoft / entra id | Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing | 25d ago |
| CVE-2026-62827 | 8.8 | high | microsoft / sharepoint server | Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a | 25d ago |
| CVE-2026-62824 | 8.8 | high | microsoft / windows 10 1607 | Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a networ | 25d ago |
| CVE-2026-62823 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent | 25d ago |
| CVE-2026-62822 | 8.8 | high | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-62818 | 8.8 | high | microsoft / windows 10 1607 | Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over | 25d ago |
| CVE-2026-62817 | 8.8 | high | microsoft / windows 10 1809 | Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | 25d ago |
| CVE-2026-62816 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to exec | 25d ago |
| CVE-2026-62800 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | 25d ago |
| CVE-2026-62795 | 8.8 | high | microsoft / windows 10 1607 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute | 25d ago |
| CVE-2026-62790 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. | 25d ago |
| CVE-2026-62785 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker | 25d ago |
| CVE-2026-62784 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to | 25d ago |
| CVE-2026-59133 | 8.8 | high | microsoft / windows app | Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized atta | 25d ago |
| CVE-2026-59113 | 8.8 | high | microsoft / visual studio code | Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 25d ago |
| CVE-2026-57104 | 8.8 | high | microsoft / azure storage explorer | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer all | 25d ago |
| CVE-2026-49179 | 8.8 | high | microsoft / windows 10 1607 | Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory al | 25d ago |
| CVE-2026-65668 | 8.8 | high | microsoft / purview ediscovery | Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a | 30d ago |
| CVE-2026-49163 | 8.8 | high | microsoft / application insights profiler | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler al | 30d ago |
| CVE-2026-62870 | 8.8 | high | microsoft / 365 apps | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | 33d ago |
| CVE-2026-47303 | 8.8 | high | microsoft / .net | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privilege | 53d ago |
| CVE-2026-47301 | 8.8 | high | microsoft / configuration manager 2503 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges ove | 53d ago |
| CVE-2026-47300 | 8.8 | high | microsoft / .net | Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate priv | 53d ago |
| CVE-2026-58626 | 8.8 | high | microsoft / windows 10 21h2 | Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. | 53d ago |
| CVE-2026-58594 | 8.8 | high | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-58534 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privile | 53d ago |
| CVE-2026-58277 | 8.8 | high | microsoft / sharepoint server | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a n | 53d ago |
| CVE-2026-57102 | 8.8 | high | microsoft / visual studio code | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to | 53d ago |
| CVE-2026-57094 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code o | 53d ago |
| CVE-2026-57090 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code o | 53d ago |
| CVE-2026-57087 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code o | 53d ago |
| CVE-2026-56647 | 8.8 | high | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to el | 53d ago |
| CVE-2026-56642 | 8.8 | high | microsoft / fabric data warehouse | Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over | 53d ago |
| CVE-2026-56197 | 8.8 | high | microsoft / windows admin center | Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows | 53d ago |
| CVE-2026-56196 | 8.8 | high | microsoft / windows admin center | Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. | 53d ago |
| CVE-2026-56194 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over | 53d ago |