Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-6175 | Hig | 0.63 | 7.8 | 0.05 | KEV | Dec 9, 2015 | The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability." | |
| CVE-2013-0090 | Hig | 0.63 | 8.8 | 0.38 | Mar 13, 2013 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CCaret Use After Free Vulnerability." | ||
| CVE-2009-1547 | Hig | 0.63 | 8.8 | 0.37 | Oct 14, 2009 | Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability." | ||
| CVE-2009-1123 | Hig | 0.63 | 7.8 | 0.05 | KEV | Jun 10, 2009 | The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel… | |
| CVE-2026-69400 | Cri | 0.62 | 9.6 | 0.01 | Aug 20, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-70332 | Cri | 0.62 | 9.6 | 0.01 | Aug 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-62896 | Cri | 0.62 | 9.6 | 0.00 | Aug 7, 2026 | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-56161 | Cri | 0.62 | 9.6 | 0.00 | Aug 7, 2026 | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-48582 | Cri | 0.62 | 9.6 | 0.01 | Jun 19, 2026 | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-47281 | Cri | 0.62 | 9.6 | 0.01 | Jun 9, 2026 | Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-42904 | Cri | 0.62 | 9.6 | 0.00 | Jun 9, 2026 | Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2026-41615 | Cri | 0.62 | 9.6 | 0.01 | May 14, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-35428 | Cri | 0.62 | 9.6 | 0.01 | May 7, 2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-33823 | Cri | 0.62 | 9.6 | 0.01 | May 7, 2026 | Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-24303 | Cri | 0.62 | 9.6 | 0.00 | Apr 23, 2026 | Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-26135 | Cri | 0.62 | 9.6 | 0.01 | Apr 3, 2026 | Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-59218 | Cri | 0.62 | 9.6 | 0.01 | Oct 9, 2025 | Azure Entra ID Elevation of Privilege Vulnerability | ||
| CVE-2025-24054 | Med | 0.62 | 6.5 | 0.59 | KEV | Mar 11, 2025 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2025-21293 | Hig | 0.62 | 8.8 | 0.19 | Jan 14, 2025 | Active Directory Domain Services Elevation of Privilege Vulnerability | ||
| CVE-2024-38175 | Cri | 0.62 | 9.6 | 0.01 | Aug 20, 2024 | An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network. | ||
| CVE-2024-38164 | Cri | 0.62 | 9.6 | 0.01 | Jul 23, 2024 | An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link. | ||
| CVE-2024-21326 | Cri | 0.62 | 9.6 | 0.01 | Jan 26, 2024 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2023-38180 | Hig | 0.62 | 7.5 | 0.14 | KEV | Aug 8, 2023 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2023-21742 | Hig | 0.62 | 8.8 | 0.56 | Jan 10, 2023 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2021-27059 | Hig | 0.62 | 7.6 | 0.06 | KEV | Mar 11, 2021 | Microsoft Office Remote Code Execution Vulnerability | |
| CVE-2021-26412 | Cri | 0.62 | 9.1 | 0.33 | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2020-1300 | Hig | 0.62 | 8.8 | 0.60 | Jun 9, 2020 | A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into… | ||
| CVE-2019-1128 | Hig | 0.62 | 8.8 | 0.17 | Jul 15, 2019 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122,… | ||
| CVE-2019-1127 | Hig | 0.62 | 8.8 | 0.21 | Jul 15, 2019 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122,… | ||
| CVE-2019-1124 | Hig | 0.62 | 8.8 | 0.18 | Jul 15, 2019 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122,… | ||
| CVE-2019-1123 | Hig | 0.62 | 8.8 | 0.17 | Jul 15, 2019 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122,… | ||
| CVE-2019-1122 | Hig | 0.62 | 8.8 | 0.17 | Jul 15, 2019 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1123,… | ||
| CVE-2019-1121 | Hig | 0.62 | 8.8 | 0.17 | Jul 15, 2019 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1122, CVE-2019-1123,… | ||
| CVE-2019-1120 | Hig | 0.62 | 8.8 | 0.17 | Jul 15, 2019 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,… | ||
| CVE-2019-1119 | Hig | 0.62 | 8.8 | 0.19 | Jul 15, 2019 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,… | ||
| CVE-2019-1118 | Hig | 0.62 | 8.8 | 0.24 | Jul 15, 2019 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,… | ||
| CVE-2019-1117 | Hig | 0.62 | 8.8 | 0.24 | Jul 15, 2019 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,… | ||
| CVE-2019-0566 | Hig | 0.62 | 8.8 | 0.19 | Jan 8, 2019 | An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. | ||
| CVE-2016-3351 | Med | 0.62 | 6.5 | 0.26 | KEV | Sep 14, 2016 | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | |
| CVE-2016-3324 | Hig | 0.62 | 8.8 | 0.28 | Sep 14, 2016 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | ||
| CVE-2016-4135 | Hig | 0.62 | 8.8 | 0.17 | Jun 16, 2016 | Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083. | ||
| CVE-2016-0100 | Hig | 0.62 | 8.4 | 0.58 | Mar 9, 2016 | Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Library Loading Input Validation Remote Code Execution Vulnerability." | ||
| CVE-2013-7331 | Med | 0.62 | 6.5 | 0.58 | KEV | Feb 26, 2014 | The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and… | |
| CVE-2026-50516 | Cri | 0.61 | 9.4 | 0.01 | Aug 11, 2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-40379 | Cri | 0.61 | 9.3 | 0.01 | May 12, 2026 | Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-24307 | Cri | 0.61 | 9.3 | 0.01 | Jan 22, 2026 | Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-64656 | Cri | 0.61 | 9.4 | 0.01 | Nov 26, 2025 | Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-62215 | Hig | 0.61 | 7.0 | 0.06 | KEV | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-32711 | Cri | 0.61 | 9.3 | 0.08 | Jun 11, 2025 | Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-47166 | Hig | 0.61 | 8.8 | 0.15 | Jun 10, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
- risk 0.63cvss 7.8epss 0.05
The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability."
- risk 0.63cvss 8.8epss 0.38
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CCaret Use After Free Vulnerability."
- risk 0.63cvss 8.8epss 0.37
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability."
- risk 0.63cvss 7.8epss 0.05
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel…
- risk 0.62cvss 9.6epss 0.01
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
- risk 0.62cvss 9.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- risk 0.62cvss 9.6epss 0.00
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
- risk 0.62cvss 9.6epss 0.00
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
- risk 0.62cvss 9.6epss 0.01
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
- risk 0.62cvss 9.6epss 0.01
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
- risk 0.62cvss 9.6epss 0.00
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
- risk 0.62cvss 9.6epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.
- risk 0.62cvss 9.6epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.
- risk 0.62cvss 9.6epss 0.01
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
- risk 0.62cvss 9.6epss 0.00
Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
- risk 0.62cvss 9.6epss 0.01
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.
- risk 0.62cvss 9.6epss 0.01
Azure Entra ID Elevation of Privilege Vulnerability
- risk 0.62cvss 6.5epss 0.59
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- risk 0.62cvss 8.8epss 0.19
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.62cvss 9.6epss 0.01
An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.
- risk 0.62cvss 9.6epss 0.01
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.
- risk 0.62cvss 9.6epss 0.01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.62cvss 7.5epss 0.14
.NET and Visual Studio Denial of Service Vulnerability
- risk 0.62cvss 8.8epss 0.56
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.62cvss 7.6epss 0.06
Microsoft Office Remote Code Execution Vulnerability
- risk 0.62cvss 9.1epss 0.33
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.62cvss 8.8epss 0.60
A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into…
- risk 0.62cvss 8.8epss 0.17
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122,…
- risk 0.62cvss 8.8epss 0.21
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122,…
- risk 0.62cvss 8.8epss 0.18
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122,…
- risk 0.62cvss 8.8epss 0.17
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122,…
- risk 0.62cvss 8.8epss 0.17
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1123,…
- risk 0.62cvss 8.8epss 0.17
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1122, CVE-2019-1123,…
- risk 0.62cvss 8.8epss 0.17
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,…
- risk 0.62cvss 8.8epss 0.19
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,…
- risk 0.62cvss 8.8epss 0.24
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,…
- risk 0.62cvss 8.8epss 0.24
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,…
- risk 0.62cvss 8.8epss 0.19
An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.
- risk 0.62cvss 6.5epss 0.26
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
- risk 0.62cvss 8.8epss 0.28
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
- risk 0.62cvss 8.8epss 0.17
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
- risk 0.62cvss 8.4epss 0.58
Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Library Loading Input Validation Remote Code Execution Vulnerability."
- risk 0.62cvss 6.5epss 0.58
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and…
- risk 0.61cvss 9.4epss 0.01
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
- risk 0.61cvss 9.3epss 0.01
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
- risk 0.61cvss 9.3epss 0.01
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.61cvss 9.4epss 0.01
Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.
- risk 0.61cvss 7.0epss 0.06
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.61cvss 9.3epss 0.08
Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.61cvss 8.8epss 0.15
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Page 14 of 314