Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Total 25621 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-32203 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-07-15 N/A 7.5 HIGH
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
CVE-2026-32178 3 Apple, Linux, Microsoft 5 Macos, Linux Kernel, .net and 2 more 2026-07-15 N/A 7.5 HIGH
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32177 1 Microsoft 19 .net, .net Framework, Visual Studio 2022 and 16 more 2026-07-15 N/A 7.3 HIGH
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-26171 3 Apple, Linux, Microsoft 5 Macos, Linux Kernel, .net and 2 more 2026-07-15 N/A 7.5 HIGH
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-26130 1 Microsoft 1 Asp.net Core 2026-07-15 N/A 7.5 HIGH
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-23666 1 Microsoft 14 .net Framework, Windows 10 1607, Windows 10 1809 and 11 more 2026-07-15 N/A 7.5 HIGH
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2025-15558 2 Docker, Microsoft 2 Command Line Interface, Windows 2026-07-15 N/A 8.0 HIGH
Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a victim user opens Docker Desktop or invokes Docker CLI plugin features, and allow privilege-escalation if the docker CLI is executed as a privileged user. This issue affects Docker CLI: through 29.1.5 and Windows binaries acting as a CLI-plugin manager using the github.com/docker/cli/cli-plugins/manager https://pkg.go.dev/github.com/docker/cli@v29.1.5+incompatible/cli-plugins/manager  package, such as Docker Compose. This issue does not impact non-Windows binaries, and projects not using the plugin-manager code.
CVE-2026-34690 3 Adobe, Apple, Microsoft 3 After Effects, Macos, Windows 2026-07-14 N/A 7.8 HIGH
After Effects is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2026-56164 1 Microsoft 1 Sharepoint Server 2026-07-14 N/A 5.3 MEDIUM
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-11944 4 Apple, Linux, Microsoft and 1 more 4 Macos, Linux Kernel, Windows and 1 more 2026-07-14 N/A 6.5 MEDIUM
openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences.
CVE-2026-41109 1 Microsoft 1 Visual Studio Code 2026-07-14 N/A 8.8 HIGH
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-0247 3 Apple, Microsoft, Paloaltonetworks 3 Macos, Windows, Prisma Access Agent 2026-07-14 N/A 7.8 HIGH
Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attacker to bypass authentication controls and execute privileged operations.
CVE-2026-0246 4 Apple, Linux, Microsoft and 1 more 4 Macos, Linux Kernel, Windows and 1 more 2026-07-14 N/A 7.8 HIGH
A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally authenticated non-administrative user to escalate their privileges to root on macOS and Linux or NT AUTHORITY\SYSTEM on Windows. This allows the user to execute arbitrary code and read sensitive information otherwise accessible only to privileged accounts. The Prisma Access Agent on iOS, Android and Chrome OS are not affected.
CVE-2026-0245 3 Apple, Microsoft, Paloaltonetworks 3 Macos, Windows, Prisma Access Agent 2026-07-14 N/A 5.5 MEDIUM
Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configuration data and credentials. The Prisma Access Agent on Linux, ChromeOS, Android, and iOS are not affected.
CVE-2018-25032 12 Apple, Azul, Debian and 9 more 39 Mac Os X, Macos, Zulu and 36 more 2026-07-14 5.0 MEDIUM 7.5 HIGH
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
CVE-2026-58596 1 Microsoft 1 Edge Chromium 2026-07-14 N/A 8.3 HIGH
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58281 1 Microsoft 1 Edge Chromium 2026-07-14 N/A 8.3 HIGH
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-57211 2 Broadcom, Microsoft 2 Rabbitmq Server, Windows 2026-07-13 N/A 6.5 MEDIUM
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attacker-controlled UNC paths. This issue is fixed in versions 4.1.11 and 4.2.6.
CVE-2026-45489 1 Microsoft 1 Edge Chromium 2026-07-12 N/A 6.5 MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-21262 1 Microsoft 5 Sql Server 2016, Sql Server 2017, Sql Server 2019 and 2 more 2026-07-10 N/A 8.8 HIGH
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.