Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-29814 | Cri | 0.61 | 9.3 | 0.02 | Mar 21, 2025 | Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2024-49147 | Cri | 0.61 | 9.3 | 0.01 | Dec 12, 2024 | Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver. | ||
| CVE-2024-49038 | Cri | 0.61 | 9.3 | 0.01 | Nov 26, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network. | ||
| CVE-2024-43451 | Med | 0.61 | 6.5 | 0.84 | KEV | Nov 12, 2024 | NTLM Hash Disclosure Spoofing Vulnerability | |
| CVE-2024-38018 | Hig | 0.61 | 8.8 | 0.51 | Sep 10, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2024-38108 | Cri | 0.61 | 9.3 | 0.01 | Aug 13, 2024 | Azure Stack Hub Spoofing Vulnerability | ||
| CVE-2023-6702 | Hig | 0.61 | 8.8 | 0.44 | Dec 14, 2023 | Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2023-33157 | Hig | 0.61 | 8.8 | 0.38 | Jul 11, 2023 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2023-33131 | Hig | 0.61 | 8.8 | 0.06 | Jun 14, 2023 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2022-37961 | Hig | 0.61 | 8.8 | 0.50 | Sep 13, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2022-35823 | Hig | 0.61 | 8.8 | 0.53 | Sep 13, 2022 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2022-26904 | Hig | 0.61 | 7.0 | 0.10 | KEV | Apr 15, 2022 | Windows User Profile Service Elevation of Privilege Vulnerability | |
| CVE-2021-34481 | Hig | 0.61 | 8.8 | 0.48 | Jul 16, 2021 | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;… | ||
| CVE-2021-31962 | Cri | 0.61 | 9.4 | 0.04 | Jun 8, 2021 | Kerberos AppContainer Security Feature Bypass Vulnerability | ||
| CVE-2021-28474 | Hig | 0.61 | 8.8 | 0.51 | May 11, 2021 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2021-27068 | Hig | 0.61 | 8.8 | 0.54 | May 11, 2021 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2021-27080 | Cri | 0.61 | 9.3 | 0.01 | Mar 11, 2021 | Azure Sphere Unsigned Code Execution Vulnerability | ||
| CVE-2021-27078 | Cri | 0.61 | 9.1 | 0.20 | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2021-24093 | Hig | 0.61 | 8.8 | 0.44 | Feb 25, 2021 | Windows Graphics Component Remote Code Execution Vulnerability | ||
| CVE-2020-16875 | Hig | 0.61 | 8.4 | 0.47 | Sep 11, 2020 | A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the… | ||
| CVE-2019-1152 | Hig | 0.61 | 8.8 | 0.13 | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,… | ||
| CVE-2019-1151 | Hig | 0.61 | 8.8 | 0.15 | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,… | ||
| CVE-2019-1149 | Hig | 0.61 | 8.8 | 0.14 | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,… | ||
| CVE-2019-1145 | Hig | 0.61 | 8.8 | 0.13 | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,… | ||
| CVE-2019-1144 | Hig | 0.61 | 8.8 | 0.13 | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,… | ||
| CVE-2018-8420 | Hig | 0.61 | 8.8 | 0.49 | Sep 13, 2018 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012,… | ||
| CVE-2018-1026 | Hig | 0.61 | 8.8 | 0.42 | Apr 12, 2018 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-1030. | ||
| CVE-2016-0088 | Cri | 0.61 | 9.3 | 0.08 | Apr 12, 2016 | Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability." | ||
| CVE-2014-2815 | Hig | 0.61 | 8.8 | 0.44 | Aug 12, 2014 | Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers creation of an executable file in a startup folder, aka "OneNote Remote Code Execution Vulnerability." | ||
| CVE-2012-0003 | Hig | 0.61 | 8.1 | 0.70 | Jan 10, 2012 | Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote… | ||
| CVE-2026-62834 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-70306 | Cri | 0.60 | 9.3 | 0.01 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-59118 | Cri | 0.60 | 9.3 | 0.00 | Aug 7, 2026 | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-41090 | Cri | 0.60 | 9.3 | 0.00 | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | ||
| CVE-2026-41103 | Cri | 0.60 | 9.1 | 0.05 | May 12, 2026 | Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-40402 | Cri | 0.60 | 9.3 | 0.00 | May 12, 2026 | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-33102 | Cri | 0.60 | 9.3 | 0.00 | Apr 23, 2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-32210 | Cri | 0.60 | 9.3 | 0.01 | Apr 23, 2026 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-40372 | Cri | 0.60 | 9.1 | 0.11 | Apr 21, 2026 | Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-24305 | Cri | 0.60 | 9.3 | 0.01 | Jan 22, 2026 | Azure Entra ID Elevation of Privilege Vulnerability | ||
| CVE-2026-21264 | Cri | 0.60 | 9.3 | 0.00 | Jan 22, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-59286 | Cri | 0.60 | 9.3 | 0.01 | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-59272 | Cri | 0.60 | 9.3 | 0.01 | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. | ||
| CVE-2025-59252 | Cri | 0.60 | 9.3 | 0.01 | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-55321 | Cri | 0.60 | 9.3 | 0.00 | Oct 9, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-53778 | Hig | 0.60 | 8.8 | 0.38 | Aug 12, 2025 | Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2024-38226 | Hig | 0.60 | 7.3 | 0.03 | KEV | Sep 10, 2024 | Microsoft Publisher Security Feature Bypass Vulnerability | |
| CVE-2024-38144 | Hig | 0.60 | 8.8 | 0.32 | Aug 13, 2024 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-29990 | Cri | 0.60 | 9.0 | 0.18 | Apr 9, 2024 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | ||
| CVE-2024-21364 | Cri | 0.60 | 9.3 | 0.01 | Feb 13, 2024 | Microsoft Azure Site Recovery Elevation of Privilege Vulnerability |
- risk 0.61cvss 9.3epss 0.02
Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
- risk 0.61cvss 9.3epss 0.01
Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.
- risk 0.61cvss 9.3epss 0.01
Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.
- risk 0.61cvss 6.5epss 0.84
NTLM Hash Disclosure Spoofing Vulnerability
- risk 0.61cvss 8.8epss 0.51
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.61cvss 9.3epss 0.01
Azure Stack Hub Spoofing Vulnerability
- risk 0.61cvss 8.8epss 0.44
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.61cvss 8.8epss 0.38
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.61cvss 8.8epss 0.06
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.61cvss 8.8epss 0.50
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.61cvss 8.8epss 0.53
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.61cvss 7.0epss 0.10
Windows User Profile Service Elevation of Privilege Vulnerability
- risk 0.61cvss 8.8epss 0.48
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;…
- risk 0.61cvss 9.4epss 0.04
Kerberos AppContainer Security Feature Bypass Vulnerability
- risk 0.61cvss 8.8epss 0.51
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.61cvss 8.8epss 0.54
Visual Studio Remote Code Execution Vulnerability
- risk 0.61cvss 9.3epss 0.01
Azure Sphere Unsigned Code Execution Vulnerability
- risk 0.61cvss 9.1epss 0.20
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.61cvss 8.8epss 0.44
Windows Graphics Component Remote Code Execution Vulnerability
- risk 0.61cvss 8.4epss 0.47
A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the…
- risk 0.61cvss 8.8epss 0.13
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…
- risk 0.61cvss 8.8epss 0.15
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…
- risk 0.61cvss 8.8epss 0.14
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…
- risk 0.61cvss 8.8epss 0.13
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…
- risk 0.61cvss 8.8epss 0.13
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…
- risk 0.61cvss 8.8epss 0.49
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012,…
- risk 0.61cvss 8.8epss 0.42
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-1030.
- risk 0.61cvss 9.3epss 0.08
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability."
- risk 0.61cvss 8.8epss 0.44
Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers creation of an executable file in a startup folder, aka "OneNote Remote Code Execution Vulnerability."
- risk 0.61cvss 8.1epss 0.70
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote…
- risk 0.60cvss 9.3epss 0.00
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
- risk 0.60cvss 9.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- risk 0.60cvss 9.3epss 0.00
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
- risk 0.60cvss 9.3epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
- risk 0.60cvss 9.1epss 0.05
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.
- risk 0.60cvss 9.3epss 0.00
Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.
- risk 0.60cvss 9.3epss 0.00
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
- risk 0.60cvss 9.3epss 0.01
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.60cvss 9.1epss 0.11
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
- risk 0.60cvss 9.3epss 0.01
Azure Entra ID Elevation of Privilege Vulnerability
- risk 0.60cvss 9.3epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.
- risk 0.60cvss 9.3epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.60cvss 9.3epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.
- risk 0.60cvss 9.3epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.60cvss 9.3epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.
- risk 0.60cvss 8.8epss 0.38
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
- risk 0.60cvss 7.3epss 0.03
Microsoft Publisher Security Feature Bypass Vulnerability
- risk 0.60cvss 8.8epss 0.32
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
- risk 0.60cvss 9.0epss 0.18
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
- risk 0.60cvss 9.3epss 0.01
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
Page 15 of 314