VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2025-54364MedAug 20, 2025
    risk 0.45cvss epss 0.00

    Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing…

  • CVE-2025-54363MedAug 20, 2025
    risk 0.45cvss epss 0.00

    Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when…

  • CVE-2024-43612MedOct 8, 2024
    risk 0.45cvss 6.9epss 0.01

    Power BI Report Server Spoofing Vulnerability

  • CVE-2024-26185MedMar 12, 2024
    risk 0.45cvss 6.5epss 0.30

    Windows Compressed Folder Tampering Vulnerability

  • CVE-2024-21388MedJan 30, 2024
    risk 0.45cvss 6.5epss 0.32

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2023-36413MedNov 14, 2023
    risk 0.45cvss 6.5epss 0.30

    Microsoft Office Security Feature Bypass Vulnerability

  • CVE-2022-37974MedOct 11, 2022
    risk 0.45cvss 6.5epss 0.36

    Windows Mixed Reality Developer Tools Information Disclosure Vulnerability

  • CVE-2022-24463MedMar 9, 2022
    risk 0.45cvss 6.5epss 0.32

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2020-16988MedNov 11, 2020
    risk 0.45cvss 6.9epss 0.01

    Azure Sphere Elevation of Privilege Vulnerability

  • CVE-2020-1034MedSep 11, 2020
    risk 0.45cvss 6.8epss 0.05

    An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated…

  • CVE-2019-1310MedNov 12, 2019
    risk 0.45cvss 6.8epss 0.05

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712,…

  • CVE-2019-1309MedNov 12, 2019
    risk 0.45cvss 6.8epss 0.05

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712,…

  • CVE-2019-0712MedNov 12, 2019
    risk 0.45cvss 6.8epss 0.05

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1309,…

  • CVE-2019-1230MedOct 10, 2019
    risk 0.45cvss 6.8epss 0.06

    An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Information Disclosure Vulnerability'.

  • CVE-2019-0678MedApr 9, 2019
    risk 0.45cvss 6.8epss 0.06

    An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a…

  • CVE-2018-8438MedSep 13, 2018
    risk 0.45cvss 6.8epss 0.07

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows Server 2012 R2,…

  • CVE-2017-8623MedAug 8, 2017
    risk 0.45cvss 6.8epss 0.07

    Windows Hyper-V in Windows 10 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability".

  • CVE-2017-0234HigMay 12, 2017
    risk 0.45cvss 7.5epss 0.38

    A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229,…

  • CVE-2017-0038MedFeb 20, 2017
    risk 0.45cvss 5.5epss 0.82

    gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive…

  • CVE-2016-3198MedJun 16, 2016
    risk 0.45cvss 6.5epss 0.32

    Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."

  • CVE-2010-0488MedMar 31, 2010
    risk 0.45cvss 6.5epss 0.29

    Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure…

  • CVE-2009-2495MedJul 29, 2009
    risk 0.45cvss 6.5epss 0.34

    The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via…

  • CVE-2026-65680MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.

  • CVE-2026-70330MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-70304MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-65799MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-65798MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-65797MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-65795MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62909HigAug 11, 2026
    risk 0.44cvss 7.8epss 0.00

    Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62886HigAug 11, 2026
    risk 0.44cvss 7.8epss 0.00

    Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-62883MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62881MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62871HigAug 11, 2026
    risk 0.44cvss 7.8epss 0.00

    Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

  • CVE-2026-62769MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-62702MedAug 11, 2026
    risk 0.44cvss 6.8epss 0.01

    Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.

  • CVE-2026-62699MedAug 11, 2026
    risk 0.44cvss 6.8epss 0.00

    Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.

  • CVE-2026-66313MedAug 4, 2026
    risk 0.44cvss 6.8epss 0.00

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

  • CVE-2026-50650HigJul 14, 2026
    risk 0.44cvss 7.8epss 0.00

    Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-50649HigJul 14, 2026
    risk 0.44cvss 7.8epss 0.01

    Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

  • CVE-2026-50646HigJul 14, 2026
    risk 0.44cvss 7.8epss 0.01

    Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

  • CVE-2026-50507MedJun 9, 2026
    risk 0.44cvss 6.8epss 0.05

    Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2026-45608MedJun 9, 2026
    risk 0.44cvss 6.8epss 0.00

    Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

  • CVE-2026-45585MedMay 20, 2026
    risk 0.44cvss 6.8epss 0.01

    Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide…

  • CVE-2026-41097MedMay 12, 2026
    risk 0.44cvss 6.7epss 0.01

    Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-32170MedMay 12, 2026
    risk 0.44cvss 6.7epss 0.00

    Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

  • CVE-2026-21530MedMay 12, 2026
    risk 0.44cvss 6.7epss 0.00

    Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

  • CVE-2026-41134HigApr 22, 2026
    risk 0.44cvss 7.8epss 0.00

    Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings, URL template…

  • CVE-2026-21709MedApr 17, 2026
    risk 0.44cvss 6.7epss 0.00

    A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.

  • CVE-2026-32223MedApr 14, 2026
    risk 0.44cvss 6.8epss 0.01

    Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

Page 153 of 314