Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-41096 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2026 | Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-33109 | Cri | 0.64 | 9.9 | 0.01 | May 7, 2026 | Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | ||
| CVE-2026-21515 | Cri | 0.64 | 9.9 | 0.01 | Apr 24, 2026 | Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-32194 | Cri | 0.64 | 9.8 | 0.01 | Mar 19, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-32191 | Cri | 0.64 | 9.8 | 0.01 | Mar 19, 2026 | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-26137 | Cri | 0.64 | 9.9 | 0.01 | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-21536 | Cri | 0.64 | 9.8 | 0.02 | Mar 5, 2026 | Microsoft Devices Pricing Program Remote Code Execution Vulnerability | ||
| CVE-2026-21531 | Cri | 0.64 | 9.8 | 0.02 | Feb 10, 2026 | Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-24300 | Cri | 0.64 | 9.8 | 0.01 | Feb 5, 2026 | Azure Front Door Elevation of Privilege Vulnerability | ||
| CVE-2026-24304 | Cri | 0.64 | 9.9 | 0.01 | Jan 23, 2026 | Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-24306 | Cri | 0.64 | 9.8 | 0.01 | Jan 22, 2026 | Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-64663 | Cri | 0.64 | 9.9 | 0.01 | Dec 18, 2025 | Custom Question Answering Elevation of Privilege Vulnerability | ||
| CVE-2025-64657 | Cri | 0.64 | 9.8 | 0.01 | Nov 26, 2025 | Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-59245 | Cri | 0.64 | 9.8 | 0.01 | Nov 20, 2025 | Microsoft SharePoint Online Elevation of Privilege Vulnerability | ||
| CVE-2025-60724 | Cri | 0.64 | 9.8 | 0.06 | Nov 11, 2025 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-49708 | Cri | 0.64 | 9.9 | 0.01 | Oct 14, 2025 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-59246 | Cri | 0.64 | 9.8 | 0.07 | Oct 9, 2025 | Azure Entra ID Elevation of Privilege Vulnerability | ||
| CVE-2025-55232 | Cri | 0.64 | 9.8 | 0.02 | Sep 9, 2025 | Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-53763 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2025 | Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-53766 | Cri | 0.64 | 9.8 | 0.07 | Aug 12, 2025 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-50165 | Cri | 0.64 | 9.8 | 0.10 | Aug 12, 2025 | Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-49747 | Cri | 0.64 | 9.9 | 0.01 | Jul 18, 2025 | Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-49746 | Cri | 0.64 | 9.9 | 0.01 | Jul 18, 2025 | Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-47966 | Cri | 0.64 | 9.8 | 0.01 | Jun 5, 2025 | Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-30387 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2025 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-29827 | Cri | 0.64 | 9.9 | 0.02 | May 8, 2025 | Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-30392 | Cri | 0.64 | 9.8 | 0.01 | Apr 30, 2025 | Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-30390 | Cri | 0.64 | 9.9 | 0.01 | Apr 30, 2025 | Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-21415 | Cri | 0.64 | 9.9 | 0.01 | Jan 29, 2025 | Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-21311 | Cri | 0.64 | 9.8 | 0.02 | Jan 14, 2025 | Windows NTLM V1 Elevation of Privilege Vulnerability | ||
| CVE-2025-21307 | Cri | 0.64 | 9.8 | 0.02 | Jan 14, 2025 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | ||
| CVE-2024-43639 | Cri | 0.64 | 9.8 | 0.09 | Nov 12, 2024 | Windows KDC Proxy Remote Code Execution Vulnerability | ||
| CVE-2024-43498 | Cri | 0.64 | 9.8 | 0.04 | Nov 12, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2024-38183 | Cri | 0.64 | 9.8 | 0.01 | Sep 17, 2024 | An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network. | ||
| CVE-2024-38199 | Cri | 0.64 | 9.8 | 0.02 | Aug 13, 2024 | Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | ||
| CVE-2024-38178 | Hig | 0.64 | 7.5 | 0.41 | KEV | Aug 13, 2024 | Scripting Engine Memory Corruption Vulnerability | |
| CVE-2024-38140 | Cri | 0.64 | 9.8 | 0.04 | Aug 13, 2024 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | ||
| CVE-2024-38076 | Cri | 0.64 | 9.8 | 0.02 | Jul 9, 2024 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | ||
| CVE-2024-38074 | Cri | 0.64 | 9.8 | 0.02 | Jul 9, 2024 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | ||
| CVE-2024-3566 | Cri | 0.64 | 9.8 | 0.07 | Apr 10, 2024 | A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied. | ||
| CVE-2024-21401 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2024 | Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability | ||
| CVE-2024-21351 | Hig | 0.64 | 7.6 | 0.30 | KEV | Feb 13, 2024 | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2023-36019 | Cri | 0.64 | 9.6 | 0.16 | Dec 12, 2023 | Microsoft Power Platform Connector Spoofing Vulnerability | ||
| CVE-2023-48316 | Cri | 0.64 | 9.8 | 0.04 | Dec 5, 2023 | Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions… | ||
| CVE-2023-36424 | Hig | 0.64 | 7.8 | 0.12 | KEV | Nov 14, 2023 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2023-36036 | Hig | 0.64 | 7.8 | 0.17 | KEV | Nov 14, 2023 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
| CVE-2023-36033 | Hig | 0.64 | 7.8 | 0.12 | KEV | Nov 14, 2023 | Windows DWM Core Library Elevation of Privilege Vulnerability | |
| CVE-2023-36028 | Cri | 0.64 | 9.8 | 0.03 | Nov 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | ||
| CVE-2023-36434 | Cri | 0.64 | 9.8 | 0.02 | Oct 10, 2023 | Windows IIS Server Elevation of Privilege Vulnerability | ||
| CVE-2023-35349 | Cri | 0.64 | 9.8 | 0.03 | Oct 10, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
- risk 0.64cvss 9.8epss 0.02
Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.9epss 0.01
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
- risk 0.64cvss 9.9epss 0.01
Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.9epss 0.01
Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.02
Microsoft Devices Pricing Program Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Azure Front Door Elevation of Privilege Vulnerability
- risk 0.64cvss 9.9epss 0.01
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.01
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss 0.01
Custom Question Answering Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.01
Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.01
Microsoft SharePoint Online Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.06
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.9epss 0.01
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.07
Azure Entra ID Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.02
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.07
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.10
Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.9epss 0.01
Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss 0.01
Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.01
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.01
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss 0.02
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.01
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss 0.01
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss 0.01
Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.02
Windows NTLM V1 Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.09
Windows KDC Proxy Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.04
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.01
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.02
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
- risk 0.64cvss 7.5epss 0.41
Scripting Engine Memory Corruption Vulnerability
- risk 0.64cvss 9.8epss 0.04
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.07
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
- risk 0.64cvss 9.8epss 0.01
Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability
- risk 0.64cvss 7.6epss 0.30
Windows SmartScreen Security Feature Bypass Vulnerability
- risk 0.64cvss 9.6epss 0.16
Microsoft Power Platform Connector Spoofing Vulnerability
- risk 0.64cvss 9.8epss 0.04
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions…
- risk 0.64cvss 7.8epss 0.12
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.64cvss 7.8epss 0.17
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- risk 0.64cvss 7.8epss 0.12
Windows DWM Core Library Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.03
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows IIS Server Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.03
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Page 10 of 314