Filtered by vendor Microsoft Subscriptions
Total 22837 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-0590 2 Microsoft, Wordpress 2 Clarity, Wordpress 2025-07-12 6.1 Medium
The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing nonce validation on the edit_clarity_project_id() function. This makes it possible for unauthenticated attackers to change the project id and add malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-1999-0347 1 Microsoft 1 Internet Explorer 2025-07-12 N/A
Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.
CVE-2024-11364 2 Microsoft, Rockwellautomation 2 Windows, Arena 2025-07-11 7.3 High
Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
CVE-2025-47956 1 Microsoft 1 Windows Security App 2025-07-11 5.5 Medium
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
CVE-2025-47977 1 Microsoft 1 Nuance Digital Engagement Platform 2025-07-11 8.2 High
Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-47968 1 Microsoft 1 Autoupdate 2025-07-11 7.8 High
Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
CVE-2025-47959 1 Microsoft 2 Visual Studio, Visual Studio 2022 2025-07-11 7.1 High
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
CVE-2025-47176 1 Microsoft 5 365 Apps, Office, Office 2024 and 2 more 2025-07-11 7.8 High
'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
CVE-2025-47175 1 Microsoft 8 365 Apps, Office, Office 2016 and 5 more 2025-07-11 7.8 High
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2025-47174 1 Microsoft 6 365 Apps, Excel, Office and 3 more 2025-07-11 7.8 High
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-47173 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-07-11 7.8 High
Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47172 1 Microsoft 2 Sharepoint Enterprise Server, Sharepoint Server 2025-07-11 8.8 High
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-47171 1 Microsoft 8 365 Apps, Office, Office 2019 and 5 more 2025-07-11 6.7 Medium
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
CVE-2025-47170 1 Microsoft 2 365 Apps, Office Long Term Servicing Channel 2025-07-11 7.8 High
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47169 1 Microsoft 6 365 Apps, Office, Office Long Term Servicing Channel and 3 more 2025-07-11 7.8 High
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47168 1 Microsoft 6 365 Apps, Office, Office Long Term Servicing Channel and 3 more 2025-07-11 7.8 High
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-47167 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-07-11 8.4 High
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47166 1 Microsoft 2 Sharepoint Enterprise Server, Sharepoint Server 2025-07-11 8.8 High
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2025-47165 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-07-11 7.8 High
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-47164 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-07-11 8.4 High
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.