VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2025-29814CriMar 21, 2025
    risk 0.61cvss 9.3epss 0.02

    Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

  • CVE-2024-49147CriDec 12, 2024
    risk 0.61cvss 9.3epss 0.01

    Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.

  • CVE-2024-49038CriNov 26, 2024
    risk 0.61cvss 9.3epss 0.01

    Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.

  • CVE-2024-43451MedKEVNov 12, 2024
    risk 0.61cvss 6.5epss 0.84

    NTLM Hash Disclosure Spoofing Vulnerability

  • CVE-2024-38018HigSep 10, 2024
    risk 0.61cvss 8.8epss 0.51

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2024-38108CriAug 13, 2024
    risk 0.61cvss 9.3epss 0.01

    Azure Stack Hub Spoofing Vulnerability

  • CVE-2023-6702HigDec 14, 2023
    risk 0.61cvss 8.8epss 0.44

    Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-33157HigJul 11, 2023
    risk 0.61cvss 8.8epss 0.38

    Microsoft SharePoint Remote Code Execution Vulnerability

  • CVE-2023-33131HigJun 14, 2023
    risk 0.61cvss 8.8epss 0.06

    Microsoft Outlook Remote Code Execution Vulnerability

  • CVE-2022-37961HigSep 13, 2022
    risk 0.61cvss 8.8epss 0.50

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-35823HigSep 13, 2022
    risk 0.61cvss 8.8epss 0.53

    Microsoft SharePoint Remote Code Execution Vulnerability

  • CVE-2022-26904HigKEVApr 15, 2022
    risk 0.61cvss 7.0epss 0.10

    Windows User Profile Service Elevation of Privilege Vulnerability

  • CVE-2021-34481HigJul 16, 2021
    risk 0.61cvss 8.8epss 0.48

    A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;…

  • CVE-2021-31962CriJun 8, 2021
    risk 0.61cvss 9.4epss 0.04

    Kerberos AppContainer Security Feature Bypass Vulnerability

  • CVE-2021-28474HigMay 11, 2021
    risk 0.61cvss 8.8epss 0.51

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2021-27068HigMay 11, 2021
    risk 0.61cvss 8.8epss 0.54

    Visual Studio Remote Code Execution Vulnerability

  • CVE-2021-27080CriMar 11, 2021
    risk 0.61cvss 9.3epss 0.01

    Azure Sphere Unsigned Code Execution Vulnerability

  • CVE-2021-27078CriMar 3, 2021
    risk 0.61cvss 9.1epss 0.20

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2021-24093HigFeb 25, 2021
    risk 0.61cvss 8.8epss 0.44

    Windows Graphics Component Remote Code Execution Vulnerability

  • CVE-2020-16875HigSep 11, 2020
    risk 0.61cvss 8.4epss 0.47

    A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the…

  • CVE-2019-1152HigAug 14, 2019
    risk 0.61cvss 8.8epss 0.13

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…

  • CVE-2019-1151HigAug 14, 2019
    risk 0.61cvss 8.8epss 0.15

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…

  • CVE-2019-1149HigAug 14, 2019
    risk 0.61cvss 8.8epss 0.14

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…

  • CVE-2019-1145HigAug 14, 2019
    risk 0.61cvss 8.8epss 0.13

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…

  • CVE-2019-1144HigAug 14, 2019
    risk 0.61cvss 8.8epss 0.13

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…

  • CVE-2018-8420HigSep 13, 2018
    risk 0.61cvss 8.8epss 0.49

    A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012,…

  • CVE-2018-1026HigApr 12, 2018
    risk 0.61cvss 8.8epss 0.42

    A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-1030.

  • CVE-2016-0088CriApr 12, 2016
    risk 0.61cvss 9.3epss 0.08

    Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability."

  • CVE-2014-2815HigAug 12, 2014
    risk 0.61cvss 8.8epss 0.44

    Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers creation of an executable file in a startup folder, aka "OneNote Remote Code Execution Vulnerability."

  • CVE-2012-0003HigJan 10, 2012
    risk 0.61cvss 8.1epss 0.70

    Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote…

  • CVE-2026-62834CriAug 20, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-70306CriAug 11, 2026
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-59118CriAug 7, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-41090CriMay 22, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-41103CriMay 12, 2026
    risk 0.60cvss 9.1epss 0.05

    Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-40402CriMay 12, 2026
    risk 0.60cvss 9.3epss 0.00

    Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-33102CriApr 23, 2026
    risk 0.60cvss 9.3epss 0.00

    Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-32210CriApr 23, 2026
    risk 0.60cvss 9.3epss 0.01

    Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-40372CriApr 21, 2026
    risk 0.60cvss 9.1epss 0.11

    Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-24305CriJan 22, 2026
    risk 0.60cvss 9.3epss 0.01

    Azure Entra ID Elevation of Privilege Vulnerability

  • CVE-2026-21264CriJan 22, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-59286CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-59272CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

  • CVE-2025-59252CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-55321CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-53778HigAug 12, 2025
    risk 0.60cvss 8.8epss 0.38

    Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

  • CVE-2024-38226HigKEVSep 10, 2024
    risk 0.60cvss 7.3epss 0.03

    Microsoft Publisher Security Feature Bypass Vulnerability

  • CVE-2024-38144HigAug 13, 2024
    risk 0.60cvss 8.8epss 0.32

    Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

  • CVE-2024-29990CriApr 9, 2024
    risk 0.60cvss 9.0epss 0.18

    Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

  • CVE-2024-21364CriFeb 13, 2024
    risk 0.60cvss 9.3epss 0.01

    Microsoft Azure Site Recovery Elevation of Privilege Vulnerability

Page 15 of 314