VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2024-38024HigJul 9, 2024
    risk 0.50cvss 7.2epss 0.45

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2024-35267HigJul 9, 2024
    risk 0.50cvss 7.6epss 0.02

    Azure DevOps Server Spoofing Vulnerability

  • CVE-2024-35266HigJul 9, 2024
    risk 0.50cvss 7.6epss 0.02

    Azure DevOps Server Spoofing Vulnerability

  • CVE-2023-50387HigFeb 14, 2024
    risk 0.50cvss 7.5epss 1.00

    Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with…

  • CVE-2024-21328HigFeb 13, 2024
    risk 0.50cvss 7.6epss 0.01

    Dynamics 365 Sales Spoofing Vulnerability

  • CVE-2024-21327HigFeb 13, 2024
    risk 0.50cvss 7.6epss 0.01

    Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability

  • CVE-2023-36049HigNov 14, 2023
    risk 0.50cvss 7.6epss 0.13

    .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability

  • CVE-2023-38162HigSep 12, 2023
    risk 0.50cvss 7.5epss 0.10

    DHCP Server Service Denial of Service Vulnerability

  • CVE-2023-21752HigJan 10, 2023
    risk 0.50cvss 7.1epss 0.05

    Windows Backup Service Elevation of Privilege Vulnerability

  • CVE-2022-37998HigOct 11, 2022
    risk 0.50cvss 7.7epss 0.03

    Windows Local Session Manager (LSM) Denial of Service Vulnerability

  • CVE-2022-37973HigOct 11, 2022
    risk 0.50cvss 7.7epss 0.03

    Windows Local Session Manager (LSM) Denial of Service Vulnerability

  • CVE-2022-38012HigSep 13, 2022
    risk 0.50cvss 7.7epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2022-23263HigFeb 7, 2022
    risk 0.50cvss 7.7epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2022-21891HigJan 11, 2022
    risk 0.50cvss 7.6epss 0.02

    Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability

  • CVE-2021-41349MedNov 10, 2021
    risk 0.50cvss 6.5epss 0.93

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2021-40484HigOct 13, 2021
    risk 0.50cvss 7.6epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-40483HigOct 13, 2021
    risk 0.50cvss 7.6epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-40463HigOct 13, 2021
    risk 0.50cvss 7.7epss 0.03

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

  • CVE-2021-38650HigSep 15, 2021
    risk 0.50cvss 7.6epss 0.02

    Microsoft Office Spoofing Vulnerability

  • CVE-2021-36940HigAug 12, 2021
    risk 0.50cvss 7.6epss 0.04

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-26429HigAug 12, 2021
    risk 0.50cvss 7.7epss 0.01

    Azure Sphere Elevation of Privilege Vulnerability

  • CVE-2021-33758HigJul 14, 2021
    risk 0.50cvss 7.7epss 0.03

    Windows Hyper-V Denial of Service Vulnerability

  • CVE-2021-31984HigJul 14, 2021
    risk 0.50cvss 7.6epss 0.02

    Power BI Remote Code Execution Vulnerability

  • CVE-2021-31206HigJul 14, 2021
    risk 0.50cvss 7.6epss 0.13

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2021-31964HigJun 8, 2021
    risk 0.50cvss 7.6epss 0.02

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-31948HigJun 8, 2021
    risk 0.50cvss 7.6epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-28478HigMay 11, 2021
    risk 0.50cvss 7.6epss 0.02

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-26416HigApr 13, 2021
    risk 0.50cvss 7.7epss 0.04

    Windows Hyper-V Denial of Service Vulnerability

  • CVE-2021-26859HigMar 11, 2021
    risk 0.50cvss 7.7epss 0.03

    Microsoft Power BI Information Disclosure Vulnerability

  • CVE-2021-1692HigJan 12, 2021
    risk 0.50cvss 7.7epss 0.04

    Windows Hyper-V Denial of Service Vulnerability

  • CVE-2021-1691HigJan 12, 2021
    risk 0.50cvss 7.7epss 0.04

    Windows Hyper-V Denial of Service Vulnerability

  • CVE-2021-1638HigJan 12, 2021
    risk 0.50cvss 7.7epss 0.01

    Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that…

  • CVE-2020-17096HigDec 10, 2020
    risk 0.50cvss 7.5epss 0.18

    Windows NTFS Remote Code Execution Vulnerability

  • CVE-2020-16997HigNov 11, 2020
    risk 0.50cvss 7.7epss 0.04

    Remote Desktop Protocol Server Information Disclosure Vulnerability

  • CVE-2020-16899HigOct 16, 2020
    risk 0.50cvss 7.5epss 0.13

    A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could cause a target system to stop responding. To exploit this vulnerability, an…

  • CVE-2020-16896HigOct 16, 2020
    risk 0.50cvss 7.5epss 0.13

    An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further…

  • CVE-2020-16894HigOct 16, 2020
    risk 0.50cvss 7.7epss 0.05

    A denial of service vulnerability exists when Windows Network Address Translation (NAT) on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server…

  • CVE-2020-1593HigSep 11, 2020
    risk 0.50cvss 7.6epss 0.03

    A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the…

  • CVE-2020-1508HigSep 11, 2020
    risk 0.50cvss 7.6epss 0.03

    A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the…

  • CVE-2020-16872HigSep 11, 2020
    risk 0.50cvss 7.6epss 0.02

    A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…

  • CVE-2020-1403HigJul 14, 2020
    risk 0.50cvss 7.5epss 0.10

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.

  • CVE-2020-1219HigJun 9, 2020
    risk 0.50cvss 7.5epss 0.19

    A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.

  • CVE-2020-1206HigJun 9, 2020
    risk 0.50cvss 7.5epss 0.10

    An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Information Disclosure Vulnerability'.

  • CVE-2020-12695HigJun 8, 2020
    risk 0.50cvss 7.5epss 0.15

    The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

  • CVE-2020-1108HigMay 21, 2020
    risk 0.50cvss 7.5epss 0.06

    A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be…

  • CVE-2020-1062HigMay 21, 2020
    risk 0.50cvss 7.5epss 0.06

    A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully…

  • CVE-2020-1061HigMay 21, 2020
    risk 0.50cvss 7.5epss 0.03

    A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who…

  • CVE-2020-0827HigMar 12, 2020
    risk 0.50cvss 7.5epss 0.13

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0828,…

  • CVE-2020-0825HigMar 12, 2020
    risk 0.50cvss 7.5epss 0.13

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828,…

  • CVE-2012-5364HigFeb 20, 2020
    risk 0.50cvss 7.5epss 0.15

    The IPv6 implementation in Microsoft Windows 7 and earlier allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.

Page 114 of 314