CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
229 CVEs gefunden (Seite 1/1)

CVE-2026-49451 - The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common s

🏢 Microsoft 📅 30.6.2026 📊 CVSS: 7.5
7.5

CVE-2025-59868 - HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability

🏢 Microsoft 📅 27.6.2026 📊 CVSS: 5.5
5.5

CVE-2023-37524 - HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.

🏢 Microsoft 📅 27.6.2026 📊 CVSS: 7.7
7.7

CVE-2024-23581 - The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software

🏢 Microsoft 📅 26.6.2026 📊 CVSS: 6.7
6.7

CVE-2026-45677 - Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8

🏢 Microsoft 📅 24.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-56351 - n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft

🏢 Microsoft 📅 24.6.2026 📊 CVSS: 8.2
8.2

CVE-2026-56270 - Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability i

🏢 Azure 📅 24.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-47693 - Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4

🏢 Microsoft 📅 23.6.2026 📊 CVSS: 6.9
6.9

CVE-2026-54308 - n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent36

🏢 Microsoft 📅 23.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-54312 - n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with perm

🏢 Microsoft 📅 23.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-54303 - n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Mic

🏢 Microsoft 📅 23.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-48582 - Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileg

🏢 Microsoft 📅 19.6.2026 📊 CVSS: 9.6
9.6

CVE-2026-47645 - Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows

🏢 Microsoft 📅 19.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-42895 - Improper neutralization of special elements used in a command ('command injection') in Microsoft Cop

🏢 Microsoft 📅 19.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-32208 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ed

🏢 Microsoft 📅 19.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-49336 - @microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In

🏢 Microsoft 📅 19.6.2026 📊 CVSS: 0.0
0.0

CVE-2025-62821 - Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDat

🏢 Microsoft 📅 19.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-47647 - Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privilege

🏢 Microsoft 📅 18.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-50656 - Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Micros

🏢 Microsoft 📅 16.6.2026 📊 CVSS: 7.8
7.8

CVE-2024-24909 - Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vul

🏢 Dell 📅 16.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-8863 - Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker wit

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-50512 - Improper link resolution before file access ('link following') in Microsoft PC Manager allows an aut

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-50511 - Improper link resolution before file access ('link following') in Microsoft PC Manager allows an aut

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-49161 - Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security f

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-48562 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 4.6
4.6

CVE-2026-48560 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-47641 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 4.6
4.6

CVE-2026-47640 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 4.6
4.6

CVE-2026-47639 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-47638 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 4.6
4.6

CVE-2026-47637 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 4.6
4.6

CVE-2026-47636 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-47635 - Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthor

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.4
8.4

CVE-2026-47634 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-47631 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-47298 - Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.0
8.0

CVE-2026-47293 - Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.0
7.0

CVE-2026-45650 - User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthoriz

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-45647 - Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an autho

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-45645 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-45644 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Li

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.0
8.0

CVE-2026-45643 - Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-45642 - Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Servi

🏢 Azure 📅 9.6.2026 📊 CVSS: 3.9
3.9

CVE-2026-45606 - Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-45583 - Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an una

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-45504 - Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to ele

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-45503 - Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to dis

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-45502 - Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to dis

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.0
5.0

CVE-2026-45501 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-45500 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-45486 - Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-45485 - Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 3.3
3.3

CVE-2026-45484 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to el

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-45483 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 4.6
4.6

CVE-2026-45481 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-45479 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 4.6
4.6

CVE-2026-45475 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-45474 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.4
8.4

CVE-2026-45472 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.4
8.4

CVE-2026-45471 - Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-45469 - Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-45468 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 4.6
4.6

CVE-2026-45467 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 4.6
4.6

CVE-2026-45466 - Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose info

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 3.3
3.3

CVE-2026-45465 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-45464 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-45463 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.4
8.4

CVE-2026-45462 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 4.6
4.6

CVE-2026-45461 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.4
8.4

CVE-2026-45460 - Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 4.7
4.7

CVE-2026-45459 - Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a s

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 3.3
3.3

CVE-2026-45458 - Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthor

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.4
8.4

CVE-2026-45457 - Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-45456 - Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthor

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.4
8.4

CVE-2026-45455 - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 3.3
3.3

CVE-2026-45454 - Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office S

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-45453 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-44824 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44823 - Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44822 - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.2
8.2

CVE-2026-44821 - Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-44820 - Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44819 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-44818 - Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.0
7.0

CVE-2026-44817 - Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42986 - Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42902 - Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges lo

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-42835 - Improper neutralization of special elements in output used by a downstream component ('injection') i

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-41108 - Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.0
7.0

CVE-2026-41092 - Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges loca

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-40371 - Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises)

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-33113 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 9.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-32193 - Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Ku

🏢 Azure 📅 9.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-48579 - Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose info

🏢 Microsoft 📅 4.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-47655 - Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized a

🏢 Microsoft 📅 4.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-47644 - Improper neutralization of special elements in output used by a downstream component ('injection') i

🏢 Microsoft 📅 4.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-45497 - Improper neutralization of special elements used in a command ('command injection') in Microsoft Cop

🏢 Microsoft 📅 4.6.2026 📊 CVSS: 7.7
7.7

CVE-2025-71316 - SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unico

🏢 Microsoft 📅 4.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49139 - Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft

🏢 Microsoft 📅 1.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47294 - Improper neutralization of special elements used in an os command ('os command injection') in Micros

🏢 Microsoft 📅 1.6.2026 📊 CVSS: 8.0
8.0

CVE-2026-4387 - StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows sto

🏢 Microsoft 📅 29.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-46139 - In the Linux kernel, the following vulnerability has been resolved: smb: client: use kzalloc to zer

🏢 Microsoft 📅 28.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-32996 - This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

🏢 Microsoft 📅 28.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-46544 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.

🏢 Microsoft 📅 27.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-46538 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.

🏢 Microsoft 📅 27.5.2026 📊 CVSS: 5.9
5.9

CVE-2026-46416 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.

🏢 Microsoft 📅 27.5.2026 📊 CVSS: 6.3
6.3

CVE-2026-46414 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.

🏢 Microsoft 📅 27.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-46402 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.

🏢 Microsoft 📅 27.5.2026 📊 CVSS: 8.1
8.1

CVE-2026-45322 - Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microso

🏢 Microsoft 📅 27.5.2026 📊 CVSS: 7.8
7.8

CVE-2026-45108 - Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to befor

🏢 Azure 📅 27.5.2026 📊 CVSS: 8.4
8.4

CVE-2026-45659 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex

🏢 Microsoft 📅 22.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-42901 - Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges

🏢 Microsoft 📅 22.5.2026 📊 CVSS: 10.0
10.0

CVE-2026-41104 - Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacke

🏢 Microsoft 📅 22.5.2026 📊 CVSS: 10.0
10.0

CVE-2026-41090 - Improper neutralization of special elements used in a command ('command injection') in Microsoft Cop

🏢 Microsoft 📅 22.5.2026 📊 CVSS: 9.3
9.3

CVE-2026-33843 - Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C all

🏢 Azure 📅 22.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-23652 - Improper neutralization of special elements used in a command ('command injection') in Microsoft Pow

🏢 Microsoft 📅 22.5.2026 📊 CVSS: 10.0
10.0

CVE-2026-45584 - Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code ove

🏢 Microsoft 📅 20.5.2026 📊 CVSS: 8.1
8.1

CVE-2026-45498 - Microsoft Defender Denial of Service Vulnerability

🏢 Microsoft 📅 20.5.2026 📊 CVSS: 4.0
4.0

CVE-2026-41091 - Improper link resolution before file access ('link following') in Microsoft Defender allows an autho

🏢 Microsoft 📅 20.5.2026 📊 CVSS: 7.8
7.8

CVE-2026-45585 - Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as &qu

🏢 Microsoft 📅 20.5.2026 📊 CVSS: 6.8
6.8

CVE-2026-45495 - Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

🏢 Microsoft 📅 18.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-45494 - Microsoft Edge (Chromium-based) Spoofing Vulnerability

🏢 Microsoft 📅 18.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-45492 - Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypa

🏢 Microsoft 📅 18.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-46383 - Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0,

🏢 Microsoft 📅 15.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-45539 - Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.

🏢 Microsoft 📅 15.5.2026 📊 CVSS: 7.4
7.4

CVE-2026-44641 - Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12,

🏢 Microsoft 📅 15.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-24899 - Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's

🏢 Azure 📅 14.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-42897 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex

🏢 Microsoft 📅 14.5.2026 📊 CVSS: 8.1
8.1

CVE-2026-41615 - Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unau

🏢 Microsoft 📅 14.5.2026 📊 CVSS: 9.6
9.6

CVE-2026-44503 - The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okH

🏢 Microsoft 📅 14.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-42898 - Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) al

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 9.9
9.9

CVE-2026-42891 - User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) all

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-42838 - Improper neutralization of special elements in output used by a downstream component ('injection') i

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 5.4
5.4

CVE-2026-42833 - Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) al

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-42832 - Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing loca

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 7.7
7.7

CVE-2026-42831 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 7.8
7.8

CVE-2026-42177 - linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 5.3
5.3

CVE-2026-41107 - External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized atta

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 7.4
7.4

CVE-2026-41103 - Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluen

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 9.1
9.1

CVE-2026-41102 - Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoo

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-41101 - Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing l

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 7.1
7.1

CVE-2026-41096 - Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-41094 - Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an una

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-40421 - Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-40420 - Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-40419 - Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 7.8
7.8

CVE-2026-40418 - Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 7.8
7.8

CVE-2026-40416 - User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) all

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-40368 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.0
8.0

CVE-2026-40367 - Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an una

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.4
8.4

CVE-2026-40366 - Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an una

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.4
8.4

CVE-2026-40365 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-40364 - Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an una

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.4
8.4

CVE-2026-40363 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.4
8.4

CVE-2026-40362 - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 7.8
7.8

CVE-2026-40361 - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.4
8.4

CVE-2026-40360 - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 7.8
7.8

CVE-2026-40359 - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 7.8
7.8

CVE-2026-40358 - Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.4
8.4

CVE-2026-40357 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-35440 - Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-35439 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-35436 - Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-35429 - User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) all

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 4.3
4.3

CVE-2026-33821 - Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attac

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 7.7
7.7

CVE-2026-33112 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-33110 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-32185 - Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attack

🏢 Microsoft 📅 12.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-42316 - kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (

🏢 Azure 📅 11.5.2026 📊 CVSS: 6.5
6.5

CVE-2026-6093 - Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filt

🏢 Microsoft 📅 11.5.2026 📊 CVSS: 0.0
0.0

CVE-2026-43475 - In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Fix scheduling w

🏢 Microsoft 📅 8.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-41574 - Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatica

🏢 Azure 📅 8.5.2026 📊 CVSS: 9.8
9.8

CVE-2026-34327 - Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows a

🏢 Microsoft 📅 7.5.2026 📊 CVSS: 8.2
8.2

CVE-2026-33823 - Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over

🏢 Microsoft 📅 7.5.2026 📊 CVSS: 9.6
9.6

CVE-2026-33111 - Improper neutralization of special elements used in a command ('command injection') in Copilot Chat

🏢 Microsoft 📅 7.5.2026 📊 CVSS: 7.5
7.5

CVE-2026-43094 - In the Linux kernel, the following vulnerability has been resolved: ixgbevf: add missing negotiate_

🏢 F5 📅 6.5.2026 📊 CVSS: 5.5
5.5

CVE-2026-43572 - OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Mi

🏢 Microsoft 📅 5.5.2026 📊 CVSS: 5.3
5.3

CVE-2025-58074 - A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Mic

🏢 Microsoft 📅 4.5.2026 📊 CVSS: 8.8
8.8

CVE-2026-42525 - Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restr

🏢 Azure 📅 29.4.2026 📊 CVSS: 4.3
4.3

CVE-2026-35431 - Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthoriz

🏢 Microsoft 📅 23.4.2026 📊 CVSS: 10.0
10.0

CVE-2026-33819 - Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code

🏢 Microsoft 📅 23.4.2026 📊 CVSS: 10.0
10.0

CVE-2026-32210 - Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacke

🏢 Microsoft 📅 23.4.2026 📊 CVSS: 9.3
9.3

CVE-2026-32172 - Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute

🏢 Microsoft 📅 23.4.2026 📊 CVSS: 8.0
8.0

CVE-2026-26150 - Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate p

🏢 Microsoft 📅 23.4.2026 📊 CVSS: 8.6
8.6

CVE-2026-24303 - Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privile

🏢 Microsoft 📅 23.4.2026 📊 CVSS: 9.6
9.6

CVE-2026-34294 - Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (componen

🏢 Microsoft 📅 21.4.2026 📊 CVSS: 5.9
5.9

CVE-2026-40321 - DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e

🏢 Microsoft 📅 17.4.2026 📊 CVSS: 8.0
8.0

CVE-2026-40306 - DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e

🏢 Microsoft 📅 17.4.2026 📊 CVSS: 6.5
6.5

CVE-2026-40305 - DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft e

🏢 Microsoft 📅 17.4.2026 📊 CVSS: 4.3
4.3

CVE-2026-23772 - Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper

🏢 Dell 📅 16.4.2026 📊 CVSS: 7.3
7.3

CVE-2026-4682 - Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer

🏢 Microsoft 📅 15.4.2026 📊 CVSS: 0.0
0.0

CVE-2026-33825 - Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to el

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-33822 - Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 6.1
6.1

CVE-2026-33115 - Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 8.4
8.4

CVE-2026-33114 - Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 8.4
8.4

CVE-2026-33103 - Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to dis

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 5.5
5.5

CVE-2026-33095 - Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-32221 - Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execut

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 8.4
8.4

CVE-2026-32219 - Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges l

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.0
7.0

CVE-2026-32201 - Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 6.5
6.5

CVE-2026-32200 - Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locall

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-32199 - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-32198 - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-32197 - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-32190 - Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 8.4
8.4

CVE-2026-32189 - Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-32188 - Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.1
7.1

CVE-2026-32184 - Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authori

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-32181 - Improper privilege management in Microsoft Windows allows an authorized attacker to deny service loc

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 5.5
5.5

CVE-2026-32153 - Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges local

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-32091 - Concurrent execution using shared resource with improper synchronization ('race condition') in Micro

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 8.4
8.4

CVE-2026-27914 - Improper access control in Microsoft Management Console allows an authorized attacker to elevate pri

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-27909 - Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privil

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-26181 - Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privilege

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-26170 - Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privilege

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-26155 - Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 6.5
6.5

CVE-2026-26149 - Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an auth

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 9.0
9.0

CVE-2026-26143 - Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a securi

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-23657 - Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 7.8
7.8

CVE-2026-20945 - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 4.6
4.6

CVE-2026-39424 - MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, the chat export fe

🏢 Microsoft 📅 14.4.2026 📊 CVSS: 4.7
4.7

CVE-2026-0234 - An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex

🏢 Microsoft 📅 13.4.2026 📊 CVSS: 0.0
0.0

CVE-2026-33119 - User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) all

🏢 Microsoft 📅 10.4.2026 📊 CVSS: 5.4
5.4

CVE-2026-33118 - User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) all

🏢 Microsoft 📅 10.4.2026 📊 CVSS: 4.3
4.3

CVE-2026-35654 - OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Microsoft Teams feedback

🏢 Microsoft 📅 10.4.2026 📊 CVSS: 5.3
5.3

CVE-2026-34721 - Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OA

🏢 Microsoft 📅 8.4.2026 📊 CVSS: 6.5
6.5

CVE-2026-1078 - An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automatio

🏢 Microsoft 📅 7.4.2026 📊 CVSS: 0.0
0.0

CVE-2026-32186 - Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate priv

🏢 Microsoft 📅 3.4.2026 📊 CVSS: 10.0
10.0

CVE-2026-33105 - Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elev

🏢 Azure 📅 3.4.2026 📊 CVSS: 10.0
10.0

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.