VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2024-38107HigKEVAug 13, 2024
    risk 0.63cvss 7.8epss 0.02

    Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

  • CVE-2024-38080HigKEVJul 9, 2024
    risk 0.63cvss 7.8epss 0.07

    Windows Hyper-V Elevation of Privilege Vulnerability

  • CVE-2023-35618CriDec 7, 2023
    risk 0.63cvss 9.6epss 0.03

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2023-36735CriSep 15, 2023
    risk 0.63cvss 9.6epss 0.02

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2023-38146HigSep 12, 2023
    risk 0.63cvss 8.8epss 0.39

    Windows Themes Remote Code Execution Vulnerability

  • CVE-2023-36899HigAug 8, 2023
    risk 0.63cvss 8.8epss 0.77

    ASP.NET Elevation of Privilege Vulnerability

  • CVE-2023-33150CriJul 11, 2023
    risk 0.63cvss 9.6epss 0.02

    Microsoft Office Security Feature Bypass Vulnerability

  • CVE-2023-32046HigKEVJul 11, 2023
    risk 0.63cvss 7.8epss 0.10

    Windows MSHTML Platform Elevation of Privilege Vulnerability

  • CVE-2023-21823HigKEVFeb 14, 2023
    risk 0.63cvss 7.8epss 0.06

    Windows Graphics Component Remote Code Execution Vulnerability

  • CVE-2022-41125HigKEVNov 9, 2022
    risk 0.63cvss 7.8epss 0.03

    Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

  • CVE-2022-41033HigKEVOct 11, 2022
    risk 0.63cvss 7.8epss 0.02

    Windows COM+ Event System Service Elevation of Privilege Vulnerability

  • CVE-2022-38053HigOct 11, 2022
    risk 0.63cvss 8.8epss 0.76

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-33649CriAug 9, 2022
    risk 0.63cvss 9.6epss 0.02

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

  • CVE-2022-23277HigMar 9, 2022
    risk 0.63cvss 8.8epss 0.40

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2021-43905CriDec 15, 2021
    risk 0.63cvss 9.6epss 0.03

    Microsoft Office app Remote Code Execution Vulnerability

  • CVE-2021-41357HigKEVOct 13, 2021
    risk 0.63cvss 7.8epss 0.02

    Win32k Elevation of Privilege Vulnerability

  • CVE-2021-40450HigKEVOct 13, 2021
    risk 0.63cvss 7.8epss 0.02

    Win32k Elevation of Privilege Vulnerability

  • CVE-2021-38645HigKEVSep 15, 2021
    risk 0.63cvss 7.8epss 0.03

    Open Management Infrastructure Elevation of Privilege Vulnerability

  • CVE-2021-34486HigKEVAug 12, 2021
    risk 0.63cvss 7.8epss 0.09

    Windows Event Tracing Elevation of Privilege Vulnerability

  • CVE-2021-33771HigKEVJul 14, 2021
    risk 0.63cvss 7.8epss 0.10

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2021-31979HigKEVJul 14, 2021
    risk 0.63cvss 7.8epss 0.05

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2021-31196HigKEVJul 14, 2021
    risk 0.63cvss 7.2epss 0.54

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2021-31181HigMay 11, 2021
    risk 0.63cvss 8.8epss 0.30

    Microsoft SharePoint Remote Code Execution Vulnerability

  • CVE-2021-28310HigKEVApr 13, 2021
    risk 0.63cvss 7.8epss 0.08

    Win32k Elevation of Privilege Vulnerability

  • CVE-2021-21124CriFeb 9, 2021
    risk 0.63cvss 9.6epss 0.08

    Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21121CriFeb 9, 2021
    risk 0.63cvss 9.6epss 0.06

    Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-17143HigDec 10, 2020
    risk 0.63cvss 8.8epss 0.71

    Microsoft Exchange Server Information Disclosure Vulnerability

  • CVE-2020-17087HigKEVNov 11, 2020
    risk 0.63cvss 7.8epss 0.05

    Windows Kernel Local Elevation of Privilege Vulnerability

  • CVE-2020-24557HigKEVSep 1, 2020
    risk 0.63cvss 7.8epss 0.03

    A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege escalation. An…

  • CVE-2020-1421HigJul 14, 2020
    risk 0.63cvss 8.8epss 0.75

    A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution…

  • CVE-2020-1181HigJun 9, 2020
    risk 0.63cvss 8.8epss 0.69

    A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.

  • CVE-2020-1027HigKEVApr 15, 2020
    risk 0.63cvss 7.8epss 0.05

    An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.

  • CVE-2020-0968HigKEVApr 15, 2020
    risk 0.63cvss 7.5epss 0.30

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0970.

  • CVE-2019-19676CriMar 18, 2020
    risk 0.63cvss 9.6epss 0.01

    A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains…

  • CVE-2020-0872CriMar 12, 2020
    risk 0.63cvss 9.6epss 0.10

    A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'Remote Code Execution Vulnerability in Application Inspector'.

  • CVE-2019-1214HigKEVSep 11, 2019
    risk 0.63cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.

  • CVE-2019-1150HigAug 14, 2019
    risk 0.63cvss 8.8epss 0.29

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…

  • CVE-2019-0880HigKEVJul 15, 2019
    risk 0.63cvss 7.8epss 0.02

    A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.

  • CVE-2019-0859HigKEVApr 9, 2019
    risk 0.63cvss 7.8epss 0.04

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.

  • CVE-2019-0797HigKEVApr 9, 2019
    risk 0.63cvss 7.8epss 0.02

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808.

  • CVE-2019-0618HigMar 5, 2019
    risk 0.63cvss 8.8epss 0.67

    A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662.

  • CVE-2018-8653HigKEVDec 20, 2018
    risk 0.63cvss 7.5epss 0.30

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is…

  • CVE-2018-8611HigKEVDec 12, 2018
    risk 0.63cvss 7.8epss 0.04

    An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019,…

  • CVE-2018-8589HigKEVNov 14, 2018
    risk 0.63cvss 7.8epss 0.03

    An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.

  • CVE-2018-8397HigAug 15, 2018
    risk 0.63cvss 8.8epss 0.68

    A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.

  • CVE-2018-8298HigKEVJul 11, 2018
    risk 0.63cvss 7.5epss 0.75

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CVE-2018-8287,…

  • CVE-2017-0283HigJun 15, 2017
    risk 0.63cvss 8.8epss 0.39

    Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office Word Viewer, Microsoft Lync 2013…

  • CVE-2017-0084HigMar 17, 2017
    risk 0.63cvss 8.8epss 0.37

    Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web…

  • CVE-2017-0001HigKEVMar 17, 2017
    risk 0.63cvss 7.8epss 0.03

    The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted…

  • CVE-2016-0121HigMar 9, 2016
    risk 0.63cvss 8.8epss 0.41

    The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted OpenType…

Page 13 of 314