microsoft
14,170 tracked vulnerabilities.
CVE-2026-23663
HIGH
Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability
May 22, 2026
CVSS 7.5
EPSS 0.00
CVE-2026-42901
CRITICAL
Microsoft Entra ID Elevation of Privilege Vulnerability
May 22, 2026
CVSS 10.0
EPSS 0.00
CVE-2026-41104
CRITICAL
Microsoft Planetary Computer Pro Information Disclosure Vulnerability
May 22, 2026
CVSS 10.0
EPSS 0.00
CVE-2026-45659
HIGH
Microsoft SharePoint Remote Code Execution Vulnerability
May 22, 2026
CVSS 8.8
EPSS 0.01
CVE-2026-33843
CRITICAL
Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
May 22, 2026
CVSS 9.1
EPSS 0.00
CVE-2026-26147
HIGH
Azure Stack HCI Information Disclosure Vulnerability
May 22, 2026
CVSS 7.7
EPSS 0.00
CVE-2026-41090
CRITICAL
Microsoft Copilot Tampering Vulnerability
May 22, 2026
CVSS 9.3
EPSS 0.00
CVE-2026-42827
MEDIUM
M365 Copilot Information Disclosure Vulnerability
May 22, 2026
CVSS 6.5
EPSS 0.00
CVE-2026-47280
CRITICAL
Azure Resource Manager Elevation of Privilege Vulnerability
May 22, 2026
CVSS 10.0
EPSS 0.00
CVE-2026-40411
CRITICAL
Azure Virtual Network Gateway Remote Code Execution Vulnerability
May 22, 2026
CVSS 9.9
EPSS 0.00
CVE-2026-35430
HIGH
Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability
May 22, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-23652
CRITICAL
Microsoft Power Pages Remote Code Execution Vulnerability
May 22, 2026
CVSS 10.0
EPSS 0.00
CVE-2026-40412
CRITICAL
Azure Orbital Spatio Remote Code Execution Vulnerability
May 22, 2026
CVSS 10.0
EPSS 0.00
CVE-2026-45584
HIGH
Microsoft Defender Remote Code Execution Vulnerability
May 20, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-45498
MEDIUM
KEV
Microsoft Defender Denial of Service Vulnerability
May 20, 2026
CVSS 4.0
EPSS 0.04
CVE-2026-42834
HIGH
Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
May 20, 2026
CVSS 7.8
EPSS 0.00
CVE-2026-41091
HIGH
KEV
Microsoft Defender Elevation of Privilege Vulnerability
May 20, 2026
CVSS 7.8
EPSS 0.05
CVE-2026-45585
MEDIUM
Microsoft Windows 11 Version 24H2 - Windows BitLocker Security Feature Bypass Vulnerability
May 20, 2026
CVSS 6.8
EPSS 0.00
CVE-2026-45495
HIGH
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
May 18, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-45494
MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
May 18, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-45492
MEDIUM
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
May 18, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-42822
CRITICAL
Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability
May 18, 2026
CVSS 10.0
EPSS 0.00
CVE-2026-46383
MEDIUM
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
May 15, 2026
CVSS 5.5
EPSS 0.00
CVE-2026-45539
HIGH
Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project tree
May 15, 2026
CVSS 7.4
EPSS 0.00
CVE-2026-44641
HIGH
Microsoft APM: plugin.json component paths escape plugin root and copy arbitrary host files during install
May 15, 2026
CVSS 7.1
EPSS 0.00
Products
windows_server_2016 4,606
windows_server_2019 4,345
windows_server_2012 3,825
windows_server_2008 3,554
windows_10 2,974
windows_server_2022 2,699
windows_7 2,368
windows_8.1 2,216
windows_rt_8.1 2,020
windows_10_1809 1,935
windows_10_21h2 1,934
windows_10_22h2 1,932
windows_server_2022_23h2 1,666
windows_10_1607 1,658
windows_11_22h2 1,651
internet_explorer 1,635
windows_11_23h2 1,548
windows_11_24h2 1,234
windows_10_1507 1,230
windows_server_2025 1,195
office 1,032
windows_11_21h2 1,001
windows_vista 828
edge 756
windows_xp 739
windows_11 573
windows_2000 515
windows_11_25h2 502
sharepoint_server 477
365_apps 472
Quick Filters