Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

microsoft — Vulnerabilities & Security Advisories 9767

Browse all 9767 CVE security advisories affecting microsoft. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Microsoft operates as a global technology corporation primarily providing enterprise software, cloud computing services, and consumer electronics. Its extensive software portfolio, including Windows operating systems and Office suites, has historically been associated with a high volume of Common Vulnerabilities and Exposures (CVEs), currently totaling 8,272. Common vulnerability classes affecting these products include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex legacy codebases and extensive feature sets. Notable security incidents include the 2021 SolarWinds supply chain compromise, which impacted Microsoft’s Orion platform, and various critical zero-day exploits in Internet Explorer and Edge browsers. The company maintains a dedicated security response team and regularly issues patches through Windows Update to mitigate these risks, though the sheer scale of its ecosystem continues to present significant attack surfaces for threat actors seeking unauthorized access or data exfiltration.

Found 66 results / 9767Clear Filters
CriticalCVE-2025-72962026-08-13
Unauthenticated Mobile MCP access allows remote Android device control and screen disclosure · Advisory · microsoft/UFO
High2026-08-13
fix(typescript): restrict Nunjucks template execution · microsoft/prompty@e4a0ebf · GitHub
Unknown2026-08-13
fix(promptyjs): harden Nunjucks renderer · microsoft/prompty@f5c57c9 · GitHub
High2026-08-13
Merge commit from fork · microsoft/UFO@96983c7 · GitHub
HighCVE-2026-72972026-08-13
IPv6 transition address bypass of SSRF guard in URL validation · Advisory · microsoft/UFO · GitHub
CriticalCVE-2026-506562026-08-12
GitHub - MSNightmare/ShieldBreak: Windows Defender 0day vulnerability · GitHub
Critical2026-08-06
Microsoft Exchange Server SSRF致任意代码执行漏洞及POC
Critical2026-08-01
Microsoft Office 远程代码执行漏洞及PoC分析
Critical2026-07-30
Microsoft Exchange Server SSRF远程代码执行漏洞及POC
UnknownCVE-2025-663902026-07-21
GitHub - bountyyfi/Azure-APIM-Cross-Tenant-Signup-Bypass: Security advisory: Azure APIM Developer Portal allows cross-te
High2026-07-21
Azure APIM Cross-Tenant Signup Bypass · Advisory · bountyyfi/Azure-APIM-Cross-Tenant-Signup-Bypass · GitHub
High2026-07-17
Add authorization checks for DEVICE_INFO_REQUEST to prevent cross-dev… · microsoft/UFO@2558da4 · GitHub
Low2026-07-17
Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE Client to Read Another Device's system_info · Advisory · mi
Medium2026-07-17
COMMAND_RESULTS handler creates unowned sessions, allowing authenticated session-squatting denial of service · Advisory
High2026-07-17
Implement security enhancements for COMMAND_RESULTS handling to preve… · microsoft/UFO@cc653bd · GitHub
High2026-07-17
fix: sanitizes the client class and namespace names to avoid code injection by gavinbarron · Pull Request #7884 · micros
High2026-07-17
fix(security): disable executable frontmatter in TypeScript loader · microsoft/prompty@c27402d · GitHub
High2026-07-17
Release Release 4.5.6 of Microsoft plugins for Moodle 4.5 · microsoft/o365-moodle · GitHub
CriticalCVE-2026-55982026-07-17
Arbitrary file read via file reference expansion · Advisory · microsoft/prompty · GitHub
HighGHSA-r94h-fpcp-2qm82026-07-17
Generation-time SSRF + remote/local file inclusion via unrestricted $ref · Advisory · microsoft/kiota · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with microsoft. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.