VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2015-6175HigKEVDec 9, 2015
    risk 0.63cvss 7.8epss 0.05

    The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability."

  • CVE-2013-0090HigMar 13, 2013
    risk 0.63cvss 8.8epss 0.38

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CCaret Use After Free Vulnerability."

  • CVE-2009-1547HigOct 14, 2009
    risk 0.63cvss 8.8epss 0.37

    Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability."

  • CVE-2009-1123HigKEVJun 10, 2009
    risk 0.63cvss 7.8epss 0.05

    The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel…

  • CVE-2026-69400CriAug 20, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-70332CriAug 7, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-62896CriAug 7, 2026
    risk 0.62cvss 9.6epss 0.00

    Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-56161CriAug 7, 2026
    risk 0.62cvss 9.6epss 0.00

    Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

  • CVE-2026-48582CriJun 19, 2026
    risk 0.62cvss 9.6epss 0.01

    Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-47281CriJun 9, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-42904CriJun 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

  • CVE-2026-41615CriMay 14, 2026
    risk 0.62cvss 9.6epss 0.01

    Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-35428CriMay 7, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-33823CriMay 7, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

  • CVE-2026-24303CriApr 23, 2026
    risk 0.62cvss 9.6epss 0.00

    Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-26135CriApr 3, 2026
    risk 0.62cvss 9.6epss 0.01

    Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-59218CriOct 9, 2025
    risk 0.62cvss 9.6epss 0.01

    Azure Entra ID Elevation of Privilege Vulnerability

  • CVE-2025-24054MedKEVMar 11, 2025
    risk 0.62cvss 6.5epss 0.59

    External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-21293HigJan 14, 2025
    risk 0.62cvss 8.8epss 0.19

    Active Directory Domain Services Elevation of Privilege Vulnerability

  • CVE-2024-38175CriAug 20, 2024
    risk 0.62cvss 9.6epss 0.01

    An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.

  • CVE-2024-38164CriJul 23, 2024
    risk 0.62cvss 9.6epss 0.01

    An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.

  • CVE-2024-21326CriJan 26, 2024
    risk 0.62cvss 9.6epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2023-38180HigKEVAug 8, 2023
    risk 0.62cvss 7.5epss 0.14

    .NET and Visual Studio Denial of Service Vulnerability

  • CVE-2023-21742HigJan 10, 2023
    risk 0.62cvss 8.8epss 0.56

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2021-27059HigKEVMar 11, 2021
    risk 0.62cvss 7.6epss 0.06

    Microsoft Office Remote Code Execution Vulnerability

  • CVE-2021-26412CriMar 3, 2021
    risk 0.62cvss 9.1epss 0.33

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2020-1300HigJun 9, 2020
    risk 0.62cvss 8.8epss 0.60

    A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into…

  • CVE-2019-1128HigJul 15, 2019
    risk 0.62cvss 8.8epss 0.17

    A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122,…

  • CVE-2019-1127HigJul 15, 2019
    risk 0.62cvss 8.8epss 0.21

    A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122,…

  • CVE-2019-1124HigJul 15, 2019
    risk 0.62cvss 8.8epss 0.18

    A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122,…

  • CVE-2019-1123HigJul 15, 2019
    risk 0.62cvss 8.8epss 0.17

    A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122,…

  • CVE-2019-1122HigJul 15, 2019
    risk 0.62cvss 8.8epss 0.17

    A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1123,…

  • CVE-2019-1121HigJul 15, 2019
    risk 0.62cvss 8.8epss 0.17

    A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1122, CVE-2019-1123,…

  • CVE-2019-1120HigJul 15, 2019
    risk 0.62cvss 8.8epss 0.17

    A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,…

  • CVE-2019-1119HigJul 15, 2019
    risk 0.62cvss 8.8epss 0.19

    A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,…

  • CVE-2019-1118HigJul 15, 2019
    risk 0.62cvss 8.8epss 0.24

    A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,…

  • CVE-2019-1117HigJul 15, 2019
    risk 0.62cvss 8.8epss 0.24

    A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,…

  • CVE-2019-0566HigJan 8, 2019
    risk 0.62cvss 8.8epss 0.19

    An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.

  • CVE-2016-3351MedKEVSep 14, 2016
    risk 0.62cvss 6.5epss 0.26

    Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

  • CVE-2016-3324HigSep 14, 2016
    risk 0.62cvss 8.8epss 0.28

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

  • CVE-2016-4135HigJun 16, 2016
    risk 0.62cvss 8.8epss 0.17

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

  • CVE-2016-0100HigMar 9, 2016
    risk 0.62cvss 8.4epss 0.58

    Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Library Loading Input Validation Remote Code Execution Vulnerability."

  • CVE-2013-7331MedKEVFeb 26, 2014
    risk 0.62cvss 6.5epss 0.58

    The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and…

  • CVE-2026-50516CriAug 11, 2026
    risk 0.61cvss 9.4epss 0.01

    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-40379CriMay 12, 2026
    risk 0.61cvss 9.3epss 0.01

    Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-24307CriJan 22, 2026
    risk 0.61cvss 9.3epss 0.01

    Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-64656CriNov 26, 2025
    risk 0.61cvss 9.4epss 0.01

    Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-62215HigKEVNov 11, 2025
    risk 0.61cvss 7.0epss 0.06

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-32711CriJun 11, 2025
    risk 0.61cvss 9.3epss 0.08

    Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-47166HigJun 10, 2025
    risk 0.61cvss 8.8epss 0.15

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Page 14 of 314