Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24470 | Hig | 0.47 | 7.2 | 0.02 | Mar 9, 2022 | Azure Site Recovery Remote Code Execution Vulnerability | ||
| CVE-2022-24468 | Hig | 0.47 | 7.2 | 0.02 | Mar 9, 2022 | Azure Site Recovery Remote Code Execution Vulnerability | ||
| CVE-2022-24467 | Hig | 0.47 | 7.2 | 0.02 | Mar 9, 2022 | Azure Site Recovery Remote Code Execution Vulnerability | ||
| CVE-2022-23284 | Hig | 0.47 | 7.2 | 0.03 | Mar 9, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability | ||
| CVE-2022-23265 | Hig | 0.47 | 7.2 | 0.03 | Mar 9, 2022 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2022-23253 | Med | 0.47 | 6.5 | 0.56 | Mar 9, 2022 | Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | ||
| CVE-2022-21957 | Hig | 0.47 | 7.2 | 0.03 | Feb 9, 2022 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | ||
| CVE-2021-43889 | Hig | 0.47 | 7.2 | 0.02 | Dec 15, 2021 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2021-42294 | Hig | 0.47 | 7.2 | 0.02 | Dec 15, 2021 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2021-40481 | Hig | 0.47 | 7.1 | 0.06 | Oct 13, 2021 | Microsoft Office Visio Remote Code Execution Vulnerability | ||
| CVE-2021-40469 | Hig | 0.47 | 7.2 | 0.08 | Oct 13, 2021 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2021-34480 | Med | 0.47 | 6.8 | 0.34 | Aug 12, 2021 | Scripting Engine Memory Corruption Vulnerability | ||
| CVE-2021-34467 | Hig | 0.47 | 7.1 | 0.07 | Jul 16, 2021 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2021-31966 | Hig | 0.47 | 7.2 | 0.05 | Jun 8, 2021 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2021-31200 | Hig | 0.47 | 7.2 | 0.02 | May 11, 2021 | Common Utilities Remote Code Execution Vulnerability | ||
| CVE-2021-26422 | Hig | 0.47 | 7.2 | 0.02 | May 11, 2021 | Skype for Business and Lync Remote Code Execution Vulnerability | ||
| CVE-2021-28325 | Med | 0.47 | 6.5 | 0.62 | Apr 13, 2021 | Windows SMB Information Disclosure Vulnerability | ||
| CVE-2020-17117 | Med | 0.47 | 6.6 | 0.49 | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability | ||
| CVE-2019-1252 | Med | 0.47 | 6.5 | 0.60 | Sep 11, 2019 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1286. | ||
| CVE-2017-11823 | Med | 0.47 | 6.7 | 0.03 | Oct 13, 2017 | The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it handles Windows PowerShell sessions, aka "Microsoft Windows Security Feature Bypass". | ||
| CVE-2017-8699 | Hig | 0.47 | 7.0 | 0.21 | Sep 13, 2017 | Windows Shell in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to run arbitrary code in the context of the current user, due to… | ||
| CVE-2017-8652 | Med | 0.47 | 6.5 | 0.23 | Aug 8, 2017 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from… | ||
| CVE-2017-8588 | Hig | 0.47 | 7.0 | 0.17 | Jul 11, 2017 | Microsoft WordPad in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it parses specially… | ||
| CVE-2016-3319 | Hig | 0.47 | 7.0 | 0.19 | Aug 9, 2016 | The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allows remote attackers to execute arbitrary code via a crafted PDF file, aka "Microsoft PDF Remote Code Execution Vulnerability." | ||
| CVE-2006-7031 | Med | 0.47 | 6.5 | 0.17 | Feb 23, 2007 | Microsoft Internet Explorer 6.0.2900 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a table element with a CSS attribute that sets the position, which triggers an "unhandled exception" in mshtml.dll. | ||
| CVE-1999-0012 | Hig | 0.47 | 7.0 | 0.18 | Feb 6, 1998 | Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names. | ||
| CVE-2026-55013 | Hig | 0.46 | 7.1 | 0.00 | Aug 20, 2026 | Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally. | ||
| CVE-2026-62727 | Hig | 0.46 | 7.0 | 0.00 | Aug 19, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-70307 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65788 | Hig | 0.46 | 7.0 | 0.02 | Aug 11, 2026 | Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65783 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65782 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65781 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65780 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65779 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65778 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65776 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65678 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65675 | Hig | 0.46 | 7.1 | 0.01 | Aug 11, 2026 | No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-62908 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62892 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62788 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62780 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62774 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62773 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62766 | Hig | 0.46 | 7.0 | 0.02 | Aug 11, 2026 | Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62753 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62749 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62748 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62734 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
- risk 0.47cvss 7.2epss 0.02
Azure Site Recovery Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
Azure Site Recovery Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
Azure Site Recovery Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.03
Windows Print Spooler Elevation of Privilege Vulnerability
- risk 0.47cvss 7.2epss 0.03
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.47cvss 6.5epss 0.56
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
- risk 0.47cvss 7.2epss 0.03
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.47cvss 7.1epss 0.06
Microsoft Office Visio Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.08
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.47cvss 6.8epss 0.34
Scripting Engine Memory Corruption Vulnerability
- risk 0.47cvss 7.1epss 0.07
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.05
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
Common Utilities Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
Skype for Business and Lync Remote Code Execution Vulnerability
- risk 0.47cvss 6.5epss 0.62
Windows SMB Information Disclosure Vulnerability
- risk 0.47cvss 6.6epss 0.49
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.47cvss 6.5epss 0.60
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1286.
- risk 0.47cvss 6.7epss 0.03
The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it handles Windows PowerShell sessions, aka "Microsoft Windows Security Feature Bypass".
- risk 0.47cvss 7.0epss 0.21
Windows Shell in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to run arbitrary code in the context of the current user, due to…
- risk 0.47cvss 6.5epss 0.23
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from…
- risk 0.47cvss 7.0epss 0.17
Microsoft WordPad in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it parses specially…
- risk 0.47cvss 7.0epss 0.19
The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allows remote attackers to execute arbitrary code via a crafted PDF file, aka "Microsoft PDF Remote Code Execution Vulnerability."
- risk 0.47cvss 6.5epss 0.17
Microsoft Internet Explorer 6.0.2900 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a table element with a CSS attribute that sets the position, which triggers an "unhandled exception" in mshtml.dll.
- risk 0.47cvss 7.0epss 0.18
Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
- risk 0.46cvss 7.1epss 0.00
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.02
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.1epss 0.01
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.02
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Page 140 of 314