VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2025-49727HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49699HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-49685HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49678HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.

  • CVE-2025-48821HigJul 8, 2025
    risk 0.46cvss 7.1epss 0.00

    Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.

  • CVE-2025-48819HigJul 8, 2025
    risk 0.46cvss 7.1epss 0.00

    Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.

  • CVE-2025-47975HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-7326HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.01

    Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon…

  • CVE-2025-30378HigMay 13, 2025
    risk 0.46cvss 7.0epss 0.01

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

  • CVE-2025-29973HigMay 13, 2025
    risk 0.46cvss 7.0epss 0.00

    Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.

  • CVE-2025-29841HigMay 13, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27468HigMay 13, 2025
    risk 0.46cvss 7.0epss 0.00

    Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21264HigMay 13, 2025
    risk 0.46cvss 7.1epss 0.01

    Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2025-29809HigApr 8, 2025
    risk 0.46cvss 7.1epss 0.04

    Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.

  • CVE-2025-27732HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27492HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27491HigApr 8, 2025
    risk 0.46cvss 7.1epss 0.01

    Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.

  • CVE-2025-27478HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27475HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26665HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26649HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26640HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21191HigApr 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26627HigMar 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-25008HigMar 11, 2025
    risk 0.46cvss 7.1epss 0.01

    Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24078HigMar 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-24070HigMar 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-24036HigFeb 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

  • CVE-2025-21419HigFeb 11, 2025
    risk 0.46cvss 7.1epss 0.01

    Windows Setup Files Cleanup Elevation of Privilege Vulnerability

  • CVE-2025-21414HigFeb 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Windows Core Messaging Elevation of Privileges Vulnerability

  • CVE-2025-21379HigFeb 11, 2025
    risk 0.46cvss 7.1epss 0.01

    DHCP Client Service Remote Code Execution Vulnerability

  • CVE-2025-21194HigFeb 11, 2025
    risk 0.46cvss 7.1epss 0.01

    Microsoft Surface Security Feature Bypass Vulnerability

  • CVE-2025-21184HigFeb 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Windows Core Messaging Elevation of Privileges Vulnerability

  • CVE-2025-21346HigJan 14, 2025
    risk 0.46cvss 7.1epss 0.01

    Microsoft Office Security Feature Bypass Vulnerability

  • CVE-2025-21299HigJan 14, 2025
    risk 0.46cvss 7.1epss 0.02

    Windows Kerberos Security Feature Bypass Vulnerability

  • CVE-2024-43106HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and…

  • CVE-2024-42220HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this…

  • CVE-2024-42004HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program…

  • CVE-2024-41165HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and…

  • CVE-2024-41159HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability…

  • CVE-2024-41145HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a…

  • CVE-2024-41138HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious…

  • CVE-2024-39804HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this…

  • CVE-2024-49097HigDec 12, 2024
    risk 0.46cvss 7.0epss 0.00

    Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

  • CVE-2024-49095HigDec 12, 2024
    risk 0.46cvss 7.0epss 0.00

    Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

  • CVE-2024-49084HigDec 12, 2024
    risk 0.46cvss 7.0epss 0.00

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-49059HigDec 12, 2024
    risk 0.46cvss 7.0epss 0.00

    Microsoft Office Elevation of Privilege Vulnerability

  • CVE-2024-49049HigNov 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Visual Studio Code Remote Extension Elevation of Privilege Vulnerability

  • CVE-2024-49048HigNov 12, 2024
    risk 0.46cvss 8.1epss 0.01

    TorchGeo Remote Code Execution Vulnerability

  • CVE-2024-43615HigOct 8, 2024
    risk 0.46cvss 7.1epss 0.01

    Microsoft OpenSSH for Windows Remote Code Execution Vulnerability

Page 145 of 314