Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32176 | Med | 0.44 | 6.7 | 0.00 | Apr 14, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-32167 | Med | 0.44 | 6.7 | 0.00 | Apr 14, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-0390 | Med | 0.44 | 6.7 | 0.00 | Apr 14, 2026 | Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-34054 | Hig | 0.44 | 7.8 | 0.01 | Mar 31, 2026 | vcpkg is a free and open-source C/C++ package manager. Prior to version 3.6.1#3, vcpkg's Windows builds of OpenSSL set openssldir to a path on the build machine, making that path be attackable later on customer machines. This issue has been patched in version 3.6.1#3. | ||
| CVE-2026-24288 | Med | 0.44 | 6.8 | 0.00 | Mar 10, 2026 | Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack. | ||
| CVE-2026-26124 | Med | 0.44 | 6.7 | 0.00 | Mar 5, 2026 | '.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-23651 | Med | 0.44 | 6.7 | 0.01 | Mar 5, 2026 | Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21522 | Med | 0.44 | 6.7 | 0.00 | Feb 10, 2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-22718 | Med | 0.44 | 6.8 | 0.01 | Jan 14, 2026 | The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine. | ||
| CVE-2026-20925 | Med | 0.44 | 6.5 | 0.18 | Jan 13, 2026 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-20876 | Med | 0.44 | 6.7 | 0.01 | Jan 13, 2026 | Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20872 | Med | 0.44 | 6.5 | 0.20 | Jan 13, 2026 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-62449 | Med | 0.44 | 6.8 | 0.00 | Nov 11, 2025 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2025-62214 | Med | 0.44 | 6.7 | 0.01 | Nov 11, 2025 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally. | ||
| CVE-2025-47179 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55320 | Med | 0.44 | 6.8 | 0.01 | Oct 14, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2025-55226 | Med | 0.44 | 6.7 | 0.00 | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally. | ||
| CVE-2025-54915 | Med | 0.44 | 6.7 | 0.00 | Sep 9, 2025 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54109 | Med | 0.44 | 6.7 | 0.00 | Sep 9, 2025 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54104 | Med | 0.44 | 6.7 | 0.01 | Sep 9, 2025 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54094 | Med | 0.44 | 6.7 | 0.00 | Sep 9, 2025 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-53810 | Med | 0.44 | 6.7 | 0.00 | Sep 9, 2025 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-53808 | Med | 0.44 | 6.7 | 0.00 | Sep 9, 2025 | Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-53736 | Med | 0.44 | 6.8 | 0.01 | Aug 12, 2025 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-49751 | Med | 0.44 | 6.8 | 0.00 | Aug 12, 2025 | Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | ||
| CVE-2025-49743 | Med | 0.44 | 6.7 | 0.00 | Aug 12, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-48807 | Med | 0.44 | 6.7 | 0.00 | Aug 12, 2025 | Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally. | ||
| CVE-2025-48818 | Med | 0.44 | 6.8 | 0.00 | Jul 8, 2025 | Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2025-48811 | Med | 0.44 | 6.7 | 0.00 | Jul 8, 2025 | Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-48804 | Med | 0.44 | 6.8 | 0.01 | Jul 8, 2025 | Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2025-48803 | Med | 0.44 | 6.7 | 0.00 | Jul 8, 2025 | Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-48800 | Med | 0.44 | 6.8 | 0.01 | Jul 8, 2025 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2025-48003 | Med | 0.44 | 6.8 | 0.01 | Jul 8, 2025 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2025-48001 | Med | 0.44 | 6.8 | 0.00 | Jul 8, 2025 | Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2025-47999 | Med | 0.44 | 6.8 | 0.00 | Jul 8, 2025 | Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | ||
| CVE-2025-27488 | Med | 0.44 | 6.7 | 0.00 | May 13, 2025 | Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-26684 | Med | 0.44 | 6.7 | 0.00 | May 13, 2025 | External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-32726 | Med | 0.44 | 6.8 | 0.00 | Apr 12, 2025 | Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-26681 | Med | 0.44 | 6.7 | 0.01 | Apr 8, 2025 | Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-26637 | Med | 0.44 | 6.8 | 0.01 | Apr 8, 2025 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2025-25002 | Med | 0.44 | 6.8 | 0.01 | Apr 8, 2025 | Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. | ||
| CVE-2025-21199 | Med | 0.44 | 6.7 | 0.00 | Mar 11, 2025 | Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-21377 | Med | 0.44 | 6.5 | 0.24 | Feb 11, 2025 | NTLM Hash Disclosure Spoofing Vulnerability | ||
| CVE-2025-21349 | Med | 0.44 | 6.8 | 0.01 | Feb 11, 2025 | Windows Remote Desktop Configuration Service Tampering Vulnerability | ||
| CVE-2025-21357 | Med | 0.44 | 6.7 | 0.01 | Jan 14, 2025 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2025-21211 | Med | 0.44 | 6.8 | 0.01 | Jan 14, 2025 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2024-49110 | Med | 0.44 | 6.8 | 0.01 | Dec 12, 2024 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-49092 | Med | 0.44 | 6.8 | 0.01 | Dec 12, 2024 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-49083 | Med | 0.44 | 6.8 | 0.01 | Dec 12, 2024 | Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | ||
| CVE-2024-49082 | Med | 0.44 | 6.8 | 0.02 | Dec 12, 2024 | Windows File Explorer Information Disclosure Vulnerability |
- risk 0.44cvss 6.7epss 0.00
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
- risk 0.44cvss 7.8epss 0.01
vcpkg is a free and open-source C/C++ package manager. Prior to version 3.6.1#3, vcpkg's Windows builds of OpenSSL set openssldir to a path on the build machine, making that path be attackable later on customer machines. This issue has been patched in version 3.6.1#3.
- risk 0.44cvss 6.8epss 0.00
Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack.
- risk 0.44cvss 6.7epss 0.00
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.01
Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.01
The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine.
- risk 0.44cvss 6.5epss 0.18
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- risk 0.44cvss 6.7epss 0.01
Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.5epss 0.20
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- risk 0.44cvss 6.8epss 0.00
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally.
- risk 0.44cvss 6.7epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally.
- risk 0.44cvss 6.7epss 0.00
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network.
- risk 0.44cvss 6.7epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally.
- risk 0.44cvss 6.7epss 0.00
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.01
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.01
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.44cvss 6.8epss 0.00
Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
- risk 0.44cvss 6.7epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.
- risk 0.44cvss 6.8epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.44cvss 6.7epss 0.00
Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.01
Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.44cvss 6.7epss 0.00
Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.01
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.44cvss 6.8epss 0.01
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.44cvss 6.8epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.44cvss 6.8epss 0.00
Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
- risk 0.44cvss 6.7epss 0.00
Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.00
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.01
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.8epss 0.01
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.44cvss 6.8epss 0.01
Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.
- risk 0.44cvss 6.7epss 0.00
Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.5epss 0.24
NTLM Hash Disclosure Spoofing Vulnerability
- risk 0.44cvss 6.8epss 0.01
Windows Remote Desktop Configuration Service Tampering Vulnerability
- risk 0.44cvss 6.7epss 0.01
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.44cvss 6.8epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.44cvss 6.8epss 0.01
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability
- risk 0.44cvss 6.8epss 0.01
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability
- risk 0.44cvss 6.8epss 0.01
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability
- risk 0.44cvss 6.8epss 0.02
Windows File Explorer Information Disclosure Vulnerability
Page 154 of 314