漏洞列表 13781
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2026-26123
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose
MEDIUM 5.5 2026-03-10
microsoft authenticator
NVD
CVE-2026-26148
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized
HIGH 8.1 2026-03-10
microsoft azure_ad_ssh_login_extension_for_linux
NVD
CVE-2026-26144
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
HIGH 7.5 2026-03-10
microsoft 365_apps
NVD
CVE-2026-26141
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
HIGH 7.8 2026-03-10
microsoft azure_automation_hybrid_worker_windows_extension
NVD
CVE-2026-26134
Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileg
HIGH 7.8 2026-03-10
microsoft office
NVD
CVE-2026-26121
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform
HIGH 7.5 2026-03-10
microsoft azure_iot_explorer
NVD
CVE-2026-26118
Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate priv
HIGH 8.8 2026-03-10
microsoft azure_mcp_server microsoft azure_mcp_server
NVD
CVE-2026-26117
Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allo
HIGH 7.8 2026-03-10
microsoft arc_enabled_servers_azure_connected_machine_agent
NVD
CVE-2026-26116
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a
HIGH 8.8 2026-03-10
microsoft sql_server_2016 microsoft sql_server_2017 +3个
NVD
CVE-2026-26115
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevat
HIGH 8.8 2026-03-10
microsoft sql_server_2016 microsoft sql_server_2017 +3个
NVD
CVE-2026-26114
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
HIGH 8.8 2026-03-10
microsoft sharepoint_server microsoft sharepoint_server
NVD
CVE-2026-26113
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code lo
HIGH 8.4 2026-03-10
microsoft 365_apps microsoft office +6个
NVD
CVE-2026-26112
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute c
HIGH 7.8 2026-03-10
microsoft 365_apps microsoft excel +4个
NVD
CVE-2026-26111
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unautho
HIGH 8.8 2026-03-10
microsoft windows_server_2012 microsoft windows_server_2012 +4个
NVD
CVE-2026-26110
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthor
HIGH 8.4 2026-03-10
microsoft 365_apps microsoft office +4个
NVD
CVE-2026-26109
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally
HIGH 8.4 2026-03-10
microsoft 365_apps microsoft excel +4个
NVD
CVE-2026-26108
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code
HIGH 7.8 2026-03-10
microsoft 365_apps microsoft excel +5个
NVD
CVE-2026-26107
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
HIGH 7.8 2026-03-10
microsoft 365_apps microsoft excel +4个
NVD
CVE-2026-26106
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute co
HIGH 8.8 2026-03-10
microsoft sharepoint_server microsoft sharepoint_server +1个
NVD
CVE-2026-26105
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
HIGH 8.1 2026-03-10
microsoft sharepoint_server microsoft sharepoint_server +1个
NVD