Filtered by vendor Microsoft
Subscribe
Total
25620 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-50416 | 1 Microsoft | 4 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 and 1 more | 2026-07-20 | N/A | 3.3 LOW |
| Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. | |||||
| CVE-2026-54982 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-20 | N/A | 8.8 HIGH |
| Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. | |||||
| CVE-2026-49790 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-20 | N/A | 7.3 HIGH |
| Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | |||||
| CVE-2026-30796 | 4 Apple, Linux, Microsoft and 1 more | 4 Macos, Linux Kernel, Windows and 1 more | 2026-07-19 | N/A | 7.5 HIGH |
| Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Address book sync, Heartbeat sync loop modules) allows Sniffing Attacks. The client places the preset address-book password verbatim into the heartbeat sync JSON body (src/hbbs_http/sync.rs). Over an intact HTTPS session it is not exposed in transit, but it is a reusable shared secret rather than a zero-knowledge proof, so it is recovered by any party that becomes the API endpoint - under the re-homed/rogue API server (CVE-2026-30797) - and the leaked credential then authorizes the server-side address book. This vulnerability is associated with program files src/hbbs_http/sync.rs and program routines heartbeat sync body builder (emits preset-address-book-password). This issue affects RustDesk Client: through 1.4.8. | |||||
| CVE-2026-58644 | 1 Microsoft | 1 Sharepoint Server | 2026-07-17 | N/A | 9.8 CRITICAL |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-48272 | 2 Adobe, Microsoft | 2 Creative Cloud Desktop Application, Windows | 2026-07-17 | N/A | 7.8 HIGH |
| Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. | |||||
| CVE-2026-48344 | 2 Adobe, Microsoft | 2 Creative Cloud Desktop Application, Windows | 2026-07-17 | N/A | 7.8 HIGH |
| Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed. | |||||
| CVE-2026-58631 | 1 Microsoft | 1 Windows Admin Center | 2026-07-17 | N/A | 7.8 HIGH |
| Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally. | |||||
| CVE-2026-58636 | 1 Microsoft | 1 Pc Manager | 2026-07-17 | N/A | 7.8 HIGH |
| Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-58647 | 1 Microsoft | 1 Power Bi Report Server | 2026-07-17 | N/A | 8.0 HIGH |
| Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network. | |||||
| CVE-2026-58627 | 1 Microsoft | 7 Windows 10 1607, Windows 10 1809, Windows Server 2012 and 4 more | 2026-07-17 | N/A | 7.5 HIGH |
| Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | |||||
| CVE-2026-58617 | 1 Microsoft | 1 365 Copilot | 2026-07-16 | N/A | 8.1 HIGH |
| Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. | |||||
| CVE-2026-50670 | 1 Microsoft | 9 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 6 more | 2026-07-16 | N/A | 8.8 HIGH |
| Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-50673 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-16 | N/A | 7.8 HIGH |
| Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-50688 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-07-16 | N/A | 7.8 HIGH |
| Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-50314 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2016 and 3 more | 2026-07-16 | N/A | 7.8 HIGH |
| Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-50301 | 1 Microsoft | 5 365 Apps, Office 2016, Office 2019 and 2 more | 2026-07-16 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-48311 | 3 Adobe, Apple, Microsoft | 3 Bridge, Macos, Windows | 2026-07-16 | N/A | 7.8 HIGH |
| Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48343 | 3 Adobe, Apple, Microsoft | 3 Bridge, Macos, Windows | 2026-07-16 | N/A | 7.8 HIGH |
| Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
| CVE-2026-48342 | 3 Adobe, Apple, Microsoft | 3 Bridge, Macos, Windows | 2026-07-16 | N/A | 7.8 HIGH |
| Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |||||
