Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 24045 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-42834 1 Microsoft 1 Windows Admin Center 2026-06-01 N/A 7.8 HIGH
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-42833 1 Microsoft 1 Dynamics 365 2026-06-01 N/A 9.1 CRITICAL
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-41088 1 Microsoft 9 Windows 10 21h2, Windows 10 22h2, Windows 11 23h2 and 6 more 2026-06-01 N/A 7.8 HIGH
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-40421 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-01 N/A 4.3 MEDIUM
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-40420 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-01 N/A 8.8 HIGH
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40418 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-01 N/A 7.8 HIGH
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40414 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more 2026-06-01 N/A 7.4 HIGH
Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40413 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more 2026-06-01 N/A 7.4 HIGH
Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40401 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more 2026-06-01 N/A 7.1 HIGH
Windows TCP/IP Denial of Service Vulnerability
CVE-2026-40399 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-06-01 N/A 7.8 HIGH
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-40397 1 Microsoft 14 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 11 more 2026-06-01 N/A 7.8 HIGH
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-40369 1 Microsoft 4 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 and 1 more 2026-06-01 N/A 7.8 HIGH
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-40367 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2026-06-01 N/A 8.4 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40366 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-01 N/A 8.4 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40365 1 Microsoft 1 Sharepoint Server 2026-06-01 N/A 8.8 HIGH
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-40362 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2026-06-01 N/A 7.8 HIGH
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40358 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-01 N/A 8.4 HIGH
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-35436 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-01 N/A 8.8 HIGH
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-35429 1 Microsoft 1 Edge 2026-06-01 N/A 4.3 MEDIUM
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-35417 1 Microsoft 11 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 8 more 2026-06-01 N/A 7.8 HIGH
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.