Known Vulnerabilities for Project by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Project" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34730 | Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature all... | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-34726 | Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is d... | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-34717 | OpenProject is an open-source, web-based project management software. Prior to version 17.2.3, the =n operator in modules/rep... | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-34060 | Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp... | Not Provided | 2026-03-31 | 2026-04-02 |
| CVE-2026-34042 | act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache serv... | Not Provided | 2026-03-31 | 2026-03-31 |
| CVE-2026-34041 | act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processes the... | Not Provided | 2026-03-31 | 2026-04-02 |
| CVE-2026-33949 | Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allo... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-33742 | Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fields in... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-33700 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:project... | Not Provided | 2026-03-24 | 2026-03-24 |
| CVE-2026-33680 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.2, the `LinkSharing.ReadAll()` method al... | Not Provided | 2026-03-24 | 2026-03-26 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Project | 98 | All | All | All |
| Application | Microsoft | Project | 2013 | sp1 | All | All |
| Application | Microsoft | Project | 2010 | sp2 | All | All |
| Application | Microsoft | Project | 2007 | All | All | All |
| Application | Microsoft | Project | 2007 | sp1 | All | All |
| Application | Microsoft | Project | 2007 | sp2 | All | All |
| Application | Microsoft | Project | 2003 | All | All | All |
| Application | Microsoft | Project | 2003 | sp1 | All | All |
| Application | Microsoft | Project | 2003 | sp2 | All | All |
| Application | Microsoft | Project | 2003 | sp3 | All | All |
| Application | Microsoft | Project | 2002 | All | All | All |
| Application | Microsoft | Project | 2002 | sp1 | All | All |
| Application | Microsoft | Project | 2000 | All | All | All |
| Application | Microsoft | Project | 2000 | sr1 | All | All |
| Application | Microsoft | Project | - | All | All | All |