Filtered by vendor Microsoft
Subscribe
Total
25621 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-58285 | 1 Microsoft | 1 Edge Chromium | 2026-07-07 | N/A | 8.3 HIGH |
| Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-58284 | 1 Microsoft | 1 Edge Chromium | 2026-07-07 | N/A | 8.3 HIGH |
| Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-58276 | 1 Microsoft | 1 Edge Chromium | 2026-07-07 | N/A | 7.5 HIGH |
| Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-54998 | 1 Microsoft | 1 Exchange Online | 2026-07-07 | N/A | 8.8 HIGH |
| Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-58286 | 1 Microsoft | 1 Edge Chromium | 2026-07-07 | N/A | 8.1 HIGH |
| Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-58291 | 1 Microsoft | 1 Edge Chromium | 2026-07-06 | N/A | 6.1 MEDIUM |
| Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-58597 | 1 Microsoft | 1 Edge Chromium | 2026-07-06 | N/A | 4.3 MEDIUM |
| Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-58524 | 1 Microsoft | 1 Edge Chromium | 2026-07-06 | N/A | 5.4 MEDIUM |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-57993 | 1 Microsoft | 1 Edge Chromium | 2026-07-06 | N/A | 7.4 HIGH |
| Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-58278 | 1 Microsoft | 1 Edge Chromium | 2026-07-06 | N/A | 5.4 MEDIUM |
| Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-58282 | 1 Microsoft | 1 Edge Chromium | 2026-07-06 | N/A | 8.1 HIGH |
| Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-58283 | 1 Microsoft | 1 Edge Chromium | 2026-07-06 | N/A | 8.1 HIGH |
| Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |||||
| CVE-2026-13869 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-07-06 | N/A | 9.6 CRITICAL |
| Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-14060 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-07-06 | N/A | 7.8 HIGH |
| Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low) | |||||
| CVE-2026-14124 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-07-06 | N/A | 7.8 HIGH |
| Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low) | |||||
| CVE-2025-69624 | 2 Gonitro, Microsoft | 2 Nitro Pdf Pro, Windows | 2026-07-05 | N/A | 7.5 HIGH |
| Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.alert(app.activeDocs, true) when app.activeDocs is null), the engine routes the call through a fallback path intended for non-string arguments. In this path, js_ValueToString() is invoked on the null value and returns an invalid string pointer, which is then passed to JS_GetStringChars() without validation. Dereferencing this pointer leads to an access violation and application crash when opening a crafted PDF. For example, 14.41.1.4 and 14.42.0.34 have been reported as vulnerable. | |||||
| CVE-2025-69627 | 2 Gonitro, Microsoft | 2 Nitro Pdf Pro, Windows | 2026-07-05 | N/A | 8.4 HIGH |
| Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During execution, an internal XID object is allocated and then freed prematurely, after which the freed pointer is still passed into UI and logging helper functions. Because the freed memory region may contain unpredictable heap data or remnants of attacker-controlled JavaScript strings, downstream routines such as wcscmp() may process invalid or stale pointers. This can result in access violations and non-deterministic crashes. | |||||
| CVE-2026-50521 | 1 Microsoft | 1 Edge Chromium | 2026-07-03 | N/A | 8.3 HIGH |
| Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | |||||
| CVE-2025-36372 | 4 Ibm, Linux, Microsoft and 1 more | 4 Db2, Linux Kernel, Windows and 1 more | 2026-07-02 | N/A | 5.5 MEDIUM |
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information to an authenticated user from the monitoring and event tables. | |||||
| CVE-2026-14384 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-07-02 | N/A | 6.5 MEDIUM |
| Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
