CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
82 CVEs gefunden (Seite 1/1)

CVE-2026-32187 - Microsoft Edge (Chromium-based) Defense in Depth Vulnerability

🏢 Microsoft 📅 27.3.2026 📊 CVSS: 4.2
4.2

CVE-2026-0898 - An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio deve

🏢 Microsoft 📅 23.3.2026 📊 CVSS: 0.0
0.0

CVE-2019-25598 - HeidiSQL Portable 10.1.0.5464 contains a denial of service vulnerability that allows local attackers

🏢 Microsoft 📅 22.3.2026 📊 CVSS: 6.2
6.2

CVE-2026-32194 - Improper neutralization of special elements used in a command ('command injection') in Microsoft Bin

🏢 Microsoft 📅 19.3.2026 📊 CVSS: 9.8
9.8

CVE-2026-32191 - Improper neutralization of special elements used in an os command ('os command injection') in Micros

🏢 Microsoft 📅 19.3.2026 📊 CVSS: 9.8
9.8

CVE-2026-26139 - Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate p

🏢 Microsoft 📅 19.3.2026 📊 CVSS: 8.6
8.6

CVE-2026-26138 - Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate p

🏢 Microsoft 📅 19.3.2026 📊 CVSS: 8.6
8.6

CVE-2026-26137 - Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate pr

🏢 Microsoft 📅 19.3.2026 📊 CVSS: 9.9
9.9

CVE-2026-26136 - Improper neutralization of special elements used in a command ('command injection') in Microsoft Cop

🏢 Microsoft 📅 19.3.2026 📊 CVSS: 6.5
6.5

CVE-2026-26120 - Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tamp

🏢 Microsoft 📅 19.3.2026 📊 CVSS: 6.5
6.5

CVE-2026-25667 - ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote

🏢 Microsoft 📅 19.3.2026 📊 CVSS: 7.5
7.5

CVE-2025-58112 - Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of

🏢 Microsoft 📅 18.3.2026 📊 CVSS: 8.8
8.8

CVE-2026-0385 - Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

🏢 Microsoft 📅 16.3.2026 📊 CVSS: 5.0
5.0

CVE-2025-68623 - In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an

🏢 Microsoft 📅 11.3.2026 📊 CVSS: 8.8
8.8

CVE-2026-26123 - Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 5.5
5.5

CVE-2026-26144 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 7.5
7.5

CVE-2026-26134 - Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileg

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 7.8
7.8

CVE-2026-26114 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 8.8
8.8

CVE-2026-26113 - Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code lo

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 8.4
8.4

CVE-2026-26112 - Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute c

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 7.8
7.8

CVE-2026-26110 - Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthor

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 8.4
8.4

CVE-2026-26109 - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 8.4
8.4

CVE-2026-26108 - Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 7.8
7.8

CVE-2026-26107 - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 7.8
7.8

CVE-2026-26106 - Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute co

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 8.8
8.8

CVE-2026-26105 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 8.1
8.1

CVE-2026-25180 - Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose infor

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 5.5
5.5

CVE-2026-25169 - Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service local

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 6.2
6.2

CVE-2026-25168 - Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny ser

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 6.2
6.2

CVE-2026-25167 - Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privile

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 7.4
7.4

CVE-2026-23668 - Concurrent execution using shared resource with improper synchronization ('race condition') in Micro

🏢 Microsoft 📅 10.3.2026 📊 CVSS: 7.0
7.0

CVE-2026-21536 - Microsoft Devices Pricing Program Remote Code Execution Vulnerability

🏢 Microsoft 📅 5.3.2026 📊 CVSS: 9.8
9.8

CVE-2025-58107 - In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers

🏢 Microsoft 📅 2.3.2026 📊 CVSS: 7.5
7.5

CVE-2026-28215 - hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticate

🏢 Microsoft 📅 26.2.2026 📊 CVSS: 9.1
9.1

CVE-2026-2636 - This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" we

🏢 Microsoft 📅 25.2.2026 📊 CVSS: 5.5
5.5

CVE-2026-21535 - Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information o

🏢 Microsoft 📅 19.2.2026 📊 CVSS: 8.2
8.2

CVE-2026-26030 - Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability i

🏢 Microsoft 📅 19.2.2026 📊 CVSS: 9.9
9.9

CVE-2026-2627 - A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function

🏢 Microsoft 📅 17.2.2026 📊 CVSS: 7.8
7.8

CVE-2026-21537 - Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an

🏢 Microsoft 📅 10.2.2026 📊 CVSS: 8.8
8.8

CVE-2026-21527 - User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an

🏢 Microsoft 📅 10.2.2026 📊 CVSS: 6.5
6.5

CVE-2026-21514 - Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized

🏢 Microsoft 📅 10.2.2026 📊 CVSS: 7.8
7.8

CVE-2026-21511 - Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to per

🏢 Microsoft 📅 10.2.2026 📊 CVSS: 7.5
7.5

CVE-2026-21261 - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information

🏢 Microsoft 📅 10.2.2026 📊 CVSS: 5.5
5.5

CVE-2026-21260 - Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an una

🏢 Microsoft 📅 10.2.2026 📊 CVSS: 7.5
7.5

CVE-2026-21259 - Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate priv

🏢 Microsoft 📅 10.2.2026 📊 CVSS: 7.8
7.8

CVE-2026-21258 - Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose info

🏢 Microsoft 📅 10.2.2026 📊 CVSS: 5.5
5.5

CVE-2026-21246 - Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate

🏢 Microsoft 📅 10.2.2026 📊 CVSS: 7.8
7.8

CVE-2026-21235 - Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l

🏢 Microsoft 📅 10.2.2026 📊 CVSS: 7.3
7.3

CVE-2026-25592 - Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems.

🏢 Microsoft 📅 6.2.2026 📊 CVSS: 9.9
9.9

CVE-2026-0391 - User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows a

🏢 Microsoft 📅 5.2.2026 📊 CVSS: 6.5
6.5

CVE-2026-0948 - Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID

🏢 Microsoft 📅 4.2.2026 📊 CVSS: 6.5
6.5

CVE-2026-24838 - DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e

🏢 Microsoft 📅 28.1.2026 📊 CVSS: 9.1
9.1

CVE-2026-24837 - DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e

🏢 Microsoft 📅 28.1.2026 📊 CVSS: 7.6
7.6

CVE-2026-24836 - DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e

🏢 Microsoft 📅 28.1.2026 📊 CVSS: 7.6
7.6

CVE-2026-24833 - DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e

🏢 Microsoft 📅 28.1.2026 📊 CVSS: 7.6
7.6

CVE-2026-24784 - DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e

🏢 Microsoft 📅 28.1.2026 📊 CVSS: 6.8
6.8

CVE-2026-21509 - Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attac

🏢 Microsoft 📅 26.1.2026 📊 CVSS: 7.8
7.8

CVE-2026-21264 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ac

🏢 Microsoft 📅 22.1.2026 📊 CVSS: 9.3
9.3

CVE-2026-23873 - hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. A

🏢 Microsoft 📅 22.1.2026 📊 CVSS: 9.0
9.0

CVE-2026-21223 - Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to by

🏢 Microsoft 📅 16.1.2026 📊 CVSS: 7.1
7.1

CVE-2026-20960 - Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a

🏢 Microsoft 📅 16.1.2026 📊 CVSS: 8.0
8.0

CVE-2025-61973 - A local privilege escalation vulnerability exists during the installation of Epic Games Store via th

🏢 Microsoft 📅 15.1.2026 📊 CVSS: 8.8
8.8

CVE-2026-21265 - Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificate

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 6.4
6.4

CVE-2026-20963 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 8.8
8.8

CVE-2026-20959 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 4.6
4.6

CVE-2026-20958 - Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to d

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 5.4
5.4

CVE-2026-20957 - Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 7.8
7.8

CVE-2026-20956 - Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute c

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 7.8
7.8

CVE-2026-20955 - Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute c

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 7.8
7.8

CVE-2026-20953 - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 8.4
8.4

CVE-2026-20952 - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 8.4
8.4

CVE-2026-20951 - Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 7.8
7.8

CVE-2026-20950 - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 7.8
7.8

CVE-2026-20949 - Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a securi

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 7.8
7.8

CVE-2026-20948 - Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 7.8
7.8

CVE-2026-20947 - Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Of

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 8.8
8.8

CVE-2026-20946 - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 7.8
7.8

CVE-2026-20944 - Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 8.4
8.4

CVE-2026-20943 - Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 7.0
7.0

CVE-2026-20822 - Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l

🏢 Microsoft 📅 13.1.2026 📊 CVSS: 7.8
7.8

CVE-2025-62224 - User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows a

🏢 Microsoft 📅 7.1.2026 📊 CVSS: 5.5
5.5

CVE-2025-9611 - Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on inco

🏢 Microsoft 📅 7.1.2026 📊 CVSS: 0.0
0.0

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.