VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2021-41342MedOct 13, 2021
    risk 0.44cvss 6.8epss 0.02

    Windows MSHTML Platform Remote Code Execution Vulnerability

  • CVE-2021-34534MedAug 12, 2021
    risk 0.44cvss 6.8epss 0.02

    Windows MSHTML Platform Remote Code Execution Vulnerability

  • CVE-2021-34447MedJul 16, 2021
    risk 0.44cvss 6.8epss 0.02

    Windows MSHTML Platform Remote Code Execution Vulnerability

  • CVE-2021-34497MedJul 14, 2021
    risk 0.44cvss 6.8epss 0.02

    Windows MSHTML Platform Remote Code Execution Vulnerability

  • CVE-2021-34493MedJul 14, 2021
    risk 0.44cvss 6.7epss 0.01

    Windows Partition Management Driver Elevation of Privilege Vulnerability

  • CVE-2021-31971MedJun 8, 2021
    risk 0.44cvss 6.8epss 0.02

    Windows HTML Platforms Security Feature Bypass Vulnerability

  • CVE-2021-28458HigApr 13, 2021
    risk 0.44cvss 7.8epss 0.02

    Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability

  • CVE-2021-27092MedApr 13, 2021
    risk 0.44cvss 6.8epss 0.03

    Azure AD Web Sign-in Security Feature Bypass Vulnerability

  • CVE-2021-27075MedMar 11, 2021
    risk 0.44cvss 6.8epss 0.01

    Azure Virtual Machine Information Disclosure Vulnerability

  • CVE-2021-26854MedMar 3, 2021
    risk 0.44cvss 6.6epss 0.23

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2021-24109MedFeb 25, 2021
    risk 0.44cvss 6.8epss 0.02

    Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

  • CVE-2021-24075MedFeb 25, 2021
    risk 0.44cvss 6.8epss 0.02

    Microsoft Windows VMSwitch Denial of Service Vulnerability

  • CVE-2021-21140MedFeb 9, 2021
    risk 0.44cvss 6.8epss 0.01

    Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device.

  • CVE-2021-21135MedFeb 9, 2021
    risk 0.44cvss 6.5epss 0.19

    Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-17099MedDec 10, 2020
    risk 0.44cvss 6.8epss 0.01

    Windows Lock Screen Security Feature Bypass Vulnerability

  • CVE-2020-17063MedNov 11, 2020
    risk 0.44cvss 6.8epss 0.02

    Microsoft Office Online Spoofing Vulnerability

  • CVE-2020-17049MedNov 11, 2020
    risk 0.44cvss 6.6epss 0.14

    A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD). To exploit the vulnerability, a compromised service that is configured to use KCD could…

  • CVE-2020-16905MedOct 16, 2020
    risk 0.44cvss 6.8epss 0.01

    An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the…

  • CVE-2020-16860MedSep 11, 2020
    risk 0.44cvss 6.8epss 0.03

    A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the…

  • CVE-2020-0951MedSep 11, 2020
    risk 0.44cvss 6.7epss 0.07

    A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by…

  • CVE-2020-1398MedJul 14, 2020
    risk 0.44cvss 6.8epss 0.01

    An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vulnerability by…

  • CVE-2020-1333MedJul 14, 2020
    risk 0.44cvss 6.7epss 0.01

    An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy Processing Elevation of Privilege Vulnerability'.

  • CVE-2020-1310MedJun 9, 2020
    risk 0.44cvss 6.7epss 0.01

    An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1253.

  • CVE-2020-1258MedJun 9, 2020
    risk 0.44cvss 6.7epss 0.01

    An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.

  • CVE-2020-1253MedJun 9, 2020
    risk 0.44cvss 6.7epss 0.01

    An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1310.

  • CVE-2020-1251MedJun 9, 2020
    risk 0.44cvss 6.7epss 0.01

    An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1253, CVE-2020-1310.

  • CVE-2020-1173MedMay 21, 2020
    risk 0.44cvss 6.8epss 0.02

    A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially crafted payload and sending it to the user. The attacker who…

  • CVE-2020-1071MedMay 21, 2020
    risk 0.44cvss 6.8epss 0.01

    An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit this vulnerability an attacker would…

  • CVE-2020-0918MedApr 15, 2020
    risk 0.44cvss 6.8epss 0.01

    An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0917.

  • CVE-2020-0917MedApr 15, 2020
    risk 0.44cvss 6.8epss 0.02

    An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0918.

  • CVE-2020-0702MedFeb 11, 2020
    risk 0.44cvss 6.8epss 0.01

    A security feature bypass vulnerability exists in Surface Hub when prompting for credentials, aka 'Surface Hub Security Feature Bypass Vulnerability'.

  • CVE-2020-0689MedFeb 11, 2020
    risk 0.44cvss 6.7epss 0.01

    A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'.

  • CVE-2020-0661MedFeb 11, 2020
    risk 0.44cvss 6.8epss 0.02

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-0751.

  • CVE-2019-1314MedOct 10, 2019
    risk 0.44cvss 6.8epss 0.01

    A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen, aka 'Windows 10 Mobile Security Feature Bypass Vulnerability'.

  • CVE-2019-0966MedJul 15, 2019
    risk 0.44cvss 6.8epss 0.02

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.

  • CVE-2019-0713MedJun 12, 2019
    risk 0.44cvss 6.8epss 0.02

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system,…

  • CVE-2019-0711MedJun 12, 2019
    risk 0.44cvss 6.8epss 0.02

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system,…

  • CVE-2019-0710MedJun 12, 2019
    risk 0.44cvss 6.8epss 0.02

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system,…

  • CVE-2019-0886MedMay 16, 2019
    risk 0.44cvss 6.8epss 0.02

    An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.

  • CVE-2019-0701MedApr 9, 2019
    risk 0.44cvss 6.8epss 0.02

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0690, CVE-2019-0695.

  • CVE-2019-0695MedApr 9, 2019
    risk 0.44cvss 6.8epss 0.02

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0690, CVE-2019-0701.

  • CVE-2019-0690MedApr 9, 2019
    risk 0.44cvss 6.8epss 0.02

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0695,…

  • CVE-2018-8629HigDec 12, 2018
    risk 0.44cvss 7.5epss 0.23

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8583,…

  • CVE-2018-8372HigAug 15, 2018
    risk 0.44cvss 7.5epss 0.25

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. This CVE ID is unique from…

  • CVE-2018-8266HigAug 15, 2018
    risk 0.44cvss 7.5epss 0.27

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8380,…

  • CVE-2018-8140MedJun 14, 2018
    risk 0.44cvss 6.8epss 0.02

    An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideration for status, aka "Cortana Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10.

  • CVE-2018-3639MedMay 22, 2018
    risk 0.44cvss 5.5epss 0.61

    Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis,…

  • CVE-2018-8117MedApr 12, 2018
    risk 0.44cvss 6.8epss 0.01

    A security feature bypass vulnerability exists in the Microsoft Wireless Keyboard 850 which could allow an attacker to reuse an AES encryption key to send keystrokes to other keyboard devices or to read keystrokes sent by other keyboards for the affected devices, aka "Microsoft…

  • CVE-2017-8628MedSep 13, 2017
    risk 0.44cvss 6.8epss 0.02

    Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoofing Vulnerability".

  • CVE-2017-0196MedJul 17, 2017
    risk 0.44cvss 6.5epss 0.18

    An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

Page 157 of 314