EN
en direct
éditeur

Microsoft

826
vulnérabilités suivies
9
en exploitation active
78
critiques
26 août 2026
dernière publication
cve

Veille des vulnérabilités

identifiantvulnérabilitésévéritépublié
CVE-2019-1068Microsoft SQL Server Remote Code Execution VulnerabilityMicrosoft SQL Server Critique 26/08 CVE-2026-55013Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.Microsoft Remote Help Élevée CVSS 7.1 20/08 CVE-2026-62834Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.Microsoft Azure Data Factory Critique CVSS 9.8 20/08 CVE-2026-65770Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.Microsoft Azure Managed Instance For Apache Cassandra Critique CVSS 10 20/08 CVE-2026-65801Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.Microsoft Exchange Online Critique CVSS 10 20/08 CVE-2026-65816Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.Microsoft Azure Web Apps Critique CVSS 10 20/08 CVE-2026-66309Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.Microsoft Azure Sql Database Critique CVSS 9.1 20/08 CVE-2026-66800Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.Microsoft Azure Data Factory Élevée CVSS 7.5 20/08 CVE-2026-68782Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.Microsoft Azure Sql Database Critique CVSS 9.9 20/08 CVE-2026-68789Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.Microsoft Azure Sql Database Critique CVSS 9.9 20/08 CVE-2026-69400Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.Microsoft Azure Logic Apps Critique CVSS 9.6 20/08 CVE-2026-69519Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.Microsoft Azure Stack Hci Élevée CVSS 8.6 20/08 CVE-2026-69543Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.Microsoft Azure Virtual Machines Élevée CVSS 8.5 20/08 CVE-2026-69555Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.Microsoft Azure Arc Critique CVSS 10 20/08 CVE-2026-69558Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.Microsoft Partner Center Élevée CVSS 8.6 20/08 CVE-2026-69836Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.Microsoft Entra Id Critique CVSS 10 20/08 CVE-2026-69851Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.Microsoft Entra Id Critique CVSS 9.9 20/08 CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions Double Free VulnerabilityMicrosoft Internet Key Exchange (IKE) Service Extensions Critique 18/08 CVE-2026-55040Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.Microsoft SharePoint Critique CVSS 9.1 18/08 CVE-2026-50523Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.Microsoft Powershell Élevée CVSS 7.8 14/08 CVE-2026-69414Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.Microsoft Malware Protection Engine Élevée CVSS 7.8 14/08 CVE-2026-72970Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.Microsoft Edge Chromium Élevée CVSS 8.3 14/08 CVE-2026-42976Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-47299Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.Microsoft Azure Monitor Agent Élevée CVSS 7.2 11/08 CVE-2026-49179Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.8 11/08 CVE-2026-50472Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 11/08 CVE-2026-50516Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.Microsoft Azure Kubernetes Service Critique CVSS 9.4 11/08 CVE-2026-54113Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 11/08 CVE-2026-54981Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.Microsoft Python Élevée CVSS 7.8 11/08 CVE-2026-54984Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-56174Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 11/08 CVE-2026-56179Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.Microsoft Windows 11 24h2 Élevée CVSS 8.3 11/08 CVE-2026-57104Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.Microsoft Azure Storage Explorer Élevée CVSS 8.8 11/08 CVE-2026-58612Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.Microsoft Powershell Élevée CVSS 7.4 11/08 CVE-2026-58641Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.Microsoft .net Élevée CVSS 7.8 11/08 CVE-2026-58650Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.Microsoft Visual Studio Code Élevée CVSS 7.8 11/08 CVE-2026-58651Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.Microsoft 365 Apps Élevée CVSS 7.8 11/08 CVE-2026-59113Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.Microsoft Visual Studio Code Élevée CVSS 8.8 11/08 CVE-2026-59119Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.Microsoft Powershell Élevée CVSS 7.3 11/08 CVE-2026-59122Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 11/08 CVE-2026-59124Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.Microsoft Windows App Critique CVSS 9.8 11/08 CVE-2026-59125Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 11/08 CVE-2026-59126Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 Élevée CVSS 7 11/08 CVE-2026-59127Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-59132Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 11/08 CVE-2026-59133Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.Microsoft Windows App Élevée CVSS 8.8 11/08 CVE-2026-59134Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.1 11/08 CVE-2026-61346Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7 11/08 CVE-2026-61348Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 11/08 CVE-2026-61349Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-61352Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.1 11/08 CVE-2026-61353Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-61355Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 Élevée CVSS 7.8 11/08 CVE-2026-61356Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 11/08 CVE-2026-61357Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 11/08 CVE-2026-61358Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 11/08 CVE-2026-61359Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 Élevée CVSS 7.8 11/08 CVE-2026-61361Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.Microsoft Windows 11 24h2 Élevée CVSS 7 11/08 CVE-2026-61363Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 Élevée CVSS 8.1 11/08 CVE-2026-61364Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-61365Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-61366Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 11/08 CVE-2026-61367Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-61918Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 11/08 CVE-2026-61923Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 11/08 CVE-2026-61924Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.Microsoft Windows 10 1607 Élevée CVSS 7.5 11/08 CVE-2026-61925Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-61926Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-61927Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 11/08 CVE-2026-61929Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 Élevée CVSS 7 11/08 CVE-2026-61930Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-61932Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-61934Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 Élevée CVSS 7.8 11/08 CVE-2026-61937Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-61938Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 11/08 CVE-2026-61939Use after free in Winlogon allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 11/08 CVE-2026-62688Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 11/08 CVE-2026-62690Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7 11/08 CVE-2026-62692Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-62693Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 11/08 CVE-2026-62695Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 Élevée CVSS 7.8 11/08 CVE-2026-62696Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-62698Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-62700Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-62701Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-62702Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.Microsoft Windows 10 21h2 Élevée CVSS 8.6 11/08 CVE-2026-62705Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7 11/08 CVE-2026-62707Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-62710Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-62711Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-62712Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-62713Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 Élevée CVSS 7.8 11/08 CVE-2026-62717Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-62719Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-62721Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7.8 11/08 CVE-2026-62722Heap-based buffer overflow in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 Élevée CVSS 7.8 11/08 CVE-2026-62723Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 11/08 CVE-2026-62724Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 11/08 CVE-2026-62725Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 11/08 CVE-2026-62726Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 Élevée CVSS 7 11/08

Les 100 plus récentes.

Tapez au moins deux caractères.

naviguer ouvrir esc fermer