Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36911 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2023-36910 | Cri | 0.64 | 9.8 | 0.03 | Aug 8, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2023-35385 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2023-21709 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2023 | Microsoft Exchange Server Elevation of Privilege Vulnerability | ||
| CVE-2023-35367 | Cri | 0.64 | 9.8 | 0.02 | Jul 11, 2023 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2023-35366 | Cri | 0.64 | 9.8 | 0.02 | Jul 11, 2023 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2023-35365 | Cri | 0.64 | 9.8 | 0.02 | Jul 11, 2023 | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | ||
| CVE-2023-32057 | Cri | 0.64 | 9.8 | 0.02 | Jul 11, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2023-32031 | Hig | 0.64 | 8.8 | 0.81 | Jun 14, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2023-32015 | Cri | 0.64 | 9.8 | 0.02 | Jun 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-32014 | Cri | 0.64 | 9.8 | 0.02 | Jun 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-29363 | Cri | 0.64 | 9.8 | 0.02 | Jun 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2022-35744 | Cri | 0.64 | 9.8 | 0.02 | May 31, 2023 | Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | ||
| CVE-2023-24943 | Cri | 0.64 | 9.8 | 0.05 | May 9, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-28250 | Cri | 0.64 | 9.8 | 0.02 | Apr 11, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-23415 | Cri | 0.64 | 9.8 | 0.03 | Mar 14, 2023 | Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability | ||
| CVE-2023-23392 | Cri | 0.64 | 9.8 | 0.02 | Mar 14, 2023 | HTTP Protocol Stack Remote Code Execution Vulnerability | ||
| CVE-2023-21708 | Cri | 0.64 | 9.8 | 0.01 | Mar 14, 2023 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | ||
| CVE-2023-0754 | Cri | 0.64 | 9.8 | 0.03 | Feb 23, 2023 | The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code. | ||
| CVE-2023-21803 | Cri | 0.64 | 9.8 | 0.02 | Feb 14, 2023 | Windows iSCSI Discovery Service Remote Code Execution Vulnerability | ||
| CVE-2023-21707 | Hig | 0.64 | 8.8 | 0.82 | Feb 14, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2022-44690 | Hig | 0.64 | 8.8 | 0.82 | Dec 13, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2022-39344 | Cri | 0.64 | 9.8 | 0.02 | Nov 4, 2022 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. Prior to version 6.1.12, the USB DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memory contents. In… | ||
| CVE-2022-38028 | Hig | 0.64 | 7.8 | 0.15 | KEV | Oct 11, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2022-34722 | Cri | 0.64 | 9.8 | 0.02 | Sep 13, 2022 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | ||
| CVE-2022-30133 | Cri | 0.64 | 9.8 | 0.03 | Aug 9, 2022 | Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | ||
| CVE-2022-30216 | Hig | 0.64 | 8.8 | 0.89 | Jul 12, 2022 | Windows Server Service Tampering Vulnerability | ||
| CVE-2022-22047 | Hig | 0.64 | 7.8 | 0.19 | KEV | Jul 12, 2022 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | |
| CVE-2022-29130 | Cri | 0.64 | 9.8 | 0.04 | May 10, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-22012 | Cri | 0.64 | 9.8 | 0.04 | May 10, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-30335 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2022 | Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component. | ||
| CVE-2022-22718 | Hig | 0.64 | 7.8 | 0.18 | KEV | Feb 9, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2022-21849 | Cri | 0.64 | 9.8 | 0.06 | Jan 11, 2022 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | ||
| CVE-2021-43907 | Cri | 0.64 | 9.8 | 0.04 | Dec 15, 2021 | Visual Studio Code WSL Extension Remote Code Execution Vulnerability | ||
| CVE-2021-43899 | Cri | 0.64 | 9.8 | 0.02 | Dec 15, 2021 | Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability | ||
| CVE-2021-43215 | Cri | 0.64 | 9.8 | 0.03 | Dec 15, 2021 | iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution | ||
| CVE-2021-36948 | Hig | 0.64 | 7.8 | 0.27 | KEV | Aug 12, 2021 | Windows Update Medic Service Elevation of Privilege Vulnerability | |
| CVE-2021-34484 | Hig | 0.64 | 7.8 | 0.22 | KEV | Aug 12, 2021 | Windows User Profile Service Elevation of Privilege Vulnerability | |
| CVE-2021-31956 | Hig | 0.64 | 7.8 | 0.20 | KEV | Jun 8, 2021 | Windows NTFS Elevation of Privilege Vulnerability | |
| CVE-2021-28482 | Hig | 0.64 | 8.8 | 0.83 | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2021-26895 | Cri | 0.64 | 9.8 | 0.07 | Mar 11, 2021 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2021-26894 | Cri | 0.64 | 9.8 | 0.07 | Mar 11, 2021 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2021-26893 | Cri | 0.64 | 9.8 | 0.07 | Mar 11, 2021 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2021-24077 | Cri | 0.64 | 9.8 | 0.03 | Feb 25, 2021 | Windows Fax Service Remote Code Execution Vulnerability | ||
| CVE-2021-21132 | Cri | 0.64 | 9.6 | 0.23 | Feb 9, 2021 | Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension. | ||
| CVE-2020-17051 | Cri | 0.64 | 9.8 | 0.11 | Nov 11, 2020 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2020-1210 | Cri | 0.64 | 9.9 | 0.02 | Sep 11, 2020 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application… | ||
| CVE-2020-1025 | Cri | 0.64 | 9.8 | 0.06 | Jul 14, 2020 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit… | ||
| CVE-2020-0986 | Hig | 0.64 | 7.8 | 0.16 | KEV | Jun 9, 2020 | An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266,… | |
| CVE-2020-1026 | Cri | 0.64 | 9.8 | 0.03 | Apr 15, 2020 | A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.An attacker could potentially abuse these bugs to learn information about a… |
- risk 0.64cvss 9.8epss 0.02
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.03
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.64cvss 8.8epss 0.81
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.05
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.03
Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
HTTP Protocol Stack Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.01
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.03
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
Windows iSCSI Discovery Service Remote Code Execution Vulnerability
- risk 0.64cvss 8.8epss 0.82
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.64cvss 8.8epss 0.82
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. Prior to version 6.1.12, the USB DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memory contents. In…
- risk 0.64cvss 7.8epss 0.15
Windows Print Spooler Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.03
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
- risk 0.64cvss 8.8epss 0.89
Windows Server Service Tampering Vulnerability
- risk 0.64cvss 7.8epss 0.19
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.04
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.04
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.01
Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.
- risk 0.64cvss 7.8epss 0.18
Windows Print Spooler Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.06
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.04
Visual Studio Code WSL Extension Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.03
iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
- risk 0.64cvss 7.8epss 0.27
Windows Update Medic Service Elevation of Privilege Vulnerability
- risk 0.64cvss 7.8epss 0.22
Windows User Profile Service Elevation of Privilege Vulnerability
- risk 0.64cvss 7.8epss 0.20
Windows NTFS Elevation of Privilege Vulnerability
- risk 0.64cvss 8.8epss 0.83
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.07
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.07
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.07
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.03
Windows Fax Service Remote Code Execution Vulnerability
- risk 0.64cvss 9.6epss 0.23
Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
- risk 0.64cvss 9.8epss 0.11
Windows Network File System Remote Code Execution Vulnerability
- risk 0.64cvss 9.9epss 0.02
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application…
- risk 0.64cvss 9.8epss 0.06
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit…
- risk 0.64cvss 7.8epss 0.16
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266,…
- risk 0.64cvss 9.8epss 0.03
A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.An attacker could potentially abuse these bugs to learn information about a…
Page 11 of 314