VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2026-25181HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-23674HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-23664HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-23662HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-23661HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-58107HigMar 2, 2026
    risk 0.49cvss 7.5epss 0.00

    In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.

  • CVE-2026-21511HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.04

    Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-21260HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-21243HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

  • CVE-2026-20846HigFeb 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.

  • CVE-2026-21520HigJan 22, 2026
    risk 0.49cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector

  • CVE-2026-21226HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.

  • CVE-2026-20965HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20934HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20929HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20926HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20921HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20919HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20875HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.02

    Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

  • CVE-2026-20854HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network.

  • CVE-2026-20849HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20848HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-0386HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2025-64666HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-64658HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60704HigNov 11, 2025
    risk 0.49cvss 7.5epss 0.01

    Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-59502HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.

  • CVE-2025-59248HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-58726HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-55326HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-59251HigSep 24, 2025
    risk 0.49cvss 7.6epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2025-55243HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-54919HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

  • CVE-2025-53805HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.

  • CVE-2025-36853HigSep 8, 2025
    risk 0.49cvss 7.5epss 0.01

    A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122: Heap-based Buffer Overflow, a heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of…

  • CVE-2025-55238HigSep 4, 2025
    risk 0.49cvss 7.5epss 0.01

    Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability

  • CVE-2025-55231HigAug 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network.

  • CVE-2025-53793HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-53783HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.

  • CVE-2025-50169HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network.

  • CVE-2025-33051HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-49744HigJul 8, 2025
    risk 0.49cvss 7.0epss 0.01

    Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49718HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.03

    Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-49716HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.

  • CVE-2025-49677HigJul 8, 2025
    risk 0.49cvss 7.0epss 0.01

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-48814HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2025-47988HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2025-49715HigJun 20, 2025
    risk 0.49cvss 7.5epss 0.01

    Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-30399HigJun 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.

  • CVE-2025-33068HigJun 10, 2025
    risk 0.49cvss 7.5epss 0.02

    Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.

Page 121 of 314