vendor

microsoft

1,240 thingsrelated by NVD

Its products

windows server 2025 707 windows server 2022 670 windows 11 24h2 658 windows 11 25h2 654 windows server 2019 645 windows 10 1809 641 windows 11 26h1 634 windows 11 23h2 629 windows 10 21h2 601 windows 10 22h2 600 windows server 2016 573 windows 10 1607 569 windows server 2012 438 windows 206 365 apps 92 office 2021 89 office 2024 89 office 2019 88 microsoft 365 81 sql server 2025 56 sql server 2019 52 sql server 2022 52 office 2016 48 sql server 2017 45 excel 31 windows server 2022 23h2 28 word 26 visual studio code 21 edge chromium 14 windows server 2008 14 exchange server 11 skype for business server 10 skype for business server subscription edition 10 exchange server subscription edition 9 visual studio 2026 7 office 6 powerpoint 6 windows 10 1507 6 windows 11 22h2 6 access 5

The 40 with the most things, of 117.

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social…
CVE-2026-103626
Severity critical
Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the…
CVE-2026-103624
Severity high
chromium-browser: chromium-browser: Improper privilege management in Mojo
CVE-2026-102317
Severity high
chromium-browser: chromium-browser: Uninitialized resource in Media
CVE-2026-102315
Severity high
chromium-browser: angle: chromium-browser: Information disclosure via uninitialized resource in ANGLE
CVE-2026-102313
Severity high
Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker…
CVE-2026-95385
Severity medium
Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to…
CVE-2026-93381
Severity high
Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially…
CVE-2026-93375
Severity high
chromium-browser: chromium-browser: Incorrect authorization in Core
CVE-2026-91734
Severity high
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in…
CVE-2026-89276
Severity critical
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in…
CVE-2026-89275
Severity critical
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
CVE-2026-88097
Severity high
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized…
CVE-2026-87701
Severity critical
chromium-browser: angle: Chromium: Arbitrary code execution via buffer overflow in ANGLE
CVE-2026-87654
Severity critical
chromium-browser: angle: ANGLE: Arbitrary code execution in Google Chrome due to use-after-free
CVE-2026-87648
Severity high
Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the…
CVE-2026-87644
Severity high
chromium-browser: angle: Google Chrome (ANGLE): Arbitrary Code Execution vulnerability
CVE-2026-87621
Severity critical
Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had…
CVE-2026-87618
Severity high
chromium-browser: chromium-browser: Improper initialization in Views
CVE-2026-87616
Severity high
chromium-browser: chromium-browser: Double free in PDFium
CVE-2026-87585
Severity high
Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code…
CVE-2026-87554
Severity high
Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to…
CVE-2026-87530
Severity high
chromium-browser: chromium-browser: Type confusion in Rust
CVE-2026-87528
Severity critical
Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the…
CVE-2026-87525
Severity low
Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer…
CVE-2026-87524
Severity high
chromium-browser: angle: Chromium-browser: Arbitrary code execution via use-after-free vulnerability in ANGLE
CVE-2026-87512
Severity critical
Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code…
CVE-2026-87509
Severity high
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary…
CVE-2026-87467
Severity high
chromium-browser: chromium-browser: Race condition in Updater
CVE-2026-87457
Severity high
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-85921
Severity high
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85917
Severity high
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85893
Severity high
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an…
CVE-2026-85892
Severity high
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85889
Severity critical
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
CVE-2026-85887
Severity high
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to…
CVE-2026-85885
Severity high
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
CVE-2026-85880
Severity high Exploited yes
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
CVE-2026-85878
Severity critical
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-85875
Severity medium
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-85360
Severity high
Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in…
CVE-2026-84412
Severity critical
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform…
CVE-2026-84003
Severity high
Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.
CVE-2026-84001
Severity high
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
CVE-2026-84000
Severity high
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an…
CVE-2026-83999
Severity high
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-83998
Severity high
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-83997
Severity high
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
CVE-2026-83996
Severity high
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-83995
Severity high
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-83992
Severity high
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
CVE-2026-83990
Severity high
Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
CVE-2026-83989
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83988
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83987
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83985
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83983
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83982
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83981
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83980
Severity high
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83979
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83978
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83977
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83976
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83974
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83973
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83972
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83971
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83970
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83969
Severity high
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83968
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83967
Severity high
Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An…
CVE-2026-83964
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83955
Severity high
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83954
Severity high
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.
CVE-2026-83952
Severity high
Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to…
CVE-2026-83948
Severity high
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to…
CVE-2026-83946
Severity medium
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-83944
Severity critical
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-83942
Severity high
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
CVE-2026-83941
Severity high
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
CVE-2026-83940
Severity high
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-83939
Severity high
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation…
CVE-2026-83660
Severity critical
Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
CVE-2026-83501
Severity medium
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges…
CVE-2026-83498
Severity high
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A…
CVE-2026-82443
Severity critical
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A…
CVE-2026-82013
Severity critical
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')…
CVE-2026-82011
Severity critical
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')…
CVE-2026-82010
Severity critical
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')…
CVE-2026-82009
Severity critical
Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the…
CVE-2026-82008
Severity critical
Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the…
CVE-2026-82007
Severity high
Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of…
CVE-2026-82006
Severity high
Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the…
CVE-2026-82005
Severity high
Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the…
CVE-2026-82003
Severity high
Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An…
CVE-2026-82001
Severity medium
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could…
CVE-2026-81997
Severity medium
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker…
CVE-2026-81996
Severity high
Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability…
CVE-2026-81994
Severity medium
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. An attacker…
CVE-2026-81993
Severity medium

← Previous 1 of 13 Next →