Microsoft Security Vulnerabilities (CVE)
Explore vulnerabilities and security advisories affecting Microsoft products.
7 known CVE vulnerabilities tracked
Vulnerabilities By Year
Products Affected
All Microsoft CVEs
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network.
Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
Custom Question Answering Elevation of Privilege Vulnerability