Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-54918 | Hig | 0.59 | 8.8 | 0.19 | Sep 9, 2025 | Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-54897 | Hig | 0.59 | 8.8 | 0.19 | Sep 9, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2025-55244 | Cri | 0.59 | 9.0 | 0.01 | Sep 4, 2025 | Azure Bot Service Elevation of Privilege Vulnerability | ||
| CVE-2025-53795 | Cri | 0.59 | 9.1 | 0.01 | Aug 21, 2025 | Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-53772 | Hig | 0.59 | 8.8 | 0.22 | Aug 12, 2025 | Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network. | ||
| CVE-2025-50171 | Cri | 0.59 | 9.1 | 0.01 | Aug 12, 2025 | Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-49712 | Hig | 0.59 | 8.8 | 0.18 | Aug 12, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2025-53792 | Cri | 0.59 | 9.1 | 0.01 | Aug 7, 2025 | Azure Portal Elevation of Privilege Vulnerability | ||
| CVE-2025-47158 | Cri | 0.59 | 9.0 | 0.01 | Jul 18, 2025 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-47733 | Cri | 0.59 | 9.1 | 0.02 | May 8, 2025 | Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network | ||
| CVE-2025-27920 | Hig | 0.59 | 7.2 | 0.02 | KEV | May 5, 2025 | Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or… | |
| CVE-2025-21198 | Cri | 0.59 | 9.0 | 0.01 | Feb 11, 2025 | Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability | ||
| CVE-2025-21385 | Hig | 0.59 | 8.8 | 0.24 | Jan 9, 2025 | A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network. | ||
| CVE-2024-38124 | Cri | 0.59 | 9.0 | 0.01 | Oct 8, 2024 | Windows Netlogon Elevation of Privilege Vulnerability | ||
| CVE-2024-38220 | Cri | 0.59 | 9.0 | 0.01 | Sep 10, 2024 | Azure Stack Hub Elevation of Privilege Vulnerability | ||
| CVE-2024-38160 | Cri | 0.59 | 9.1 | 0.02 | Aug 13, 2024 | Windows Network Virtualization Remote Code Execution Vulnerability | ||
| CVE-2024-38159 | Cri | 0.59 | 9.1 | 0.02 | Aug 13, 2024 | Windows Network Virtualization Remote Code Execution Vulnerability | ||
| CVE-2024-38109 | Cri | 0.59 | 9.1 | 0.02 | Aug 13, 2024 | An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. | ||
| CVE-2024-38182 | Cri | 0.59 | 9.0 | 0.01 | Jul 31, 2024 | Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. | ||
| CVE-2024-38089 | Cri | 0.59 | 9.1 | 0.01 | Jul 9, 2024 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | ||
| CVE-2024-21400 | Cri | 0.59 | 9.0 | 0.02 | Mar 12, 2024 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | ||
| CVE-2024-21403 | Cri | 0.59 | 9.0 | 0.01 | Feb 13, 2024 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | ||
| CVE-2024-21376 | Cri | 0.59 | 9.0 | 0.01 | Feb 13, 2024 | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | ||
| CVE-2024-21345 | Hig | 0.59 | 8.8 | 0.20 | Feb 13, 2024 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-20674 | Hig | 0.59 | 8.8 | 0.17 | Jan 9, 2024 | Windows Kerberos Security Feature Bypass Vulnerability | ||
| CVE-2023-48692 | Cri | 0.59 | 9.0 | 0.03 | Dec 5, 2023 | Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions… | ||
| CVE-2023-36035 | Hig | 0.59 | 8.0 | 0.87 | Nov 14, 2023 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2023-36017 | Hig | 0.59 | 8.8 | 0.25 | Nov 14, 2023 | Windows Scripting Engine Memory Corruption Vulnerability | ||
| CVE-2023-36744 | Hig | 0.59 | 8.0 | 0.82 | Sep 12, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2023-29325 | Hig | 0.59 | 8.1 | 0.84 | May 9, 2023 | Windows OLE Remote Code Execution Vulnerability | ||
| CVE-2023-21768 | Hig | 0.59 | 7.8 | 0.65 | Jan 10, 2023 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | ||
| CVE-2022-44698 | Med | 0.59 | 5.4 | 0.76 | KEV | Dec 13, 2022 | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2022-41034 | Hig | 0.59 | 7.8 | 0.67 | Oct 11, 2022 | Visual Studio Code Remote Code Execution Vulnerability | ||
| CVE-2022-21972 | Hig | 0.59 | 8.1 | 0.80 | May 10, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-23285 | Hig | 0.59 | 8.8 | 0.26 | Mar 9, 2022 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2022-21990 | Hig | 0.59 | 8.8 | 0.19 | Mar 9, 2022 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2022-22005 | Hig | 0.59 | 8.8 | 0.17 | Feb 9, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2022-21969 | Cri | 0.59 | 9.0 | 0.01 | Jan 11, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2022-21901 | Cri | 0.59 | 9.0 | 0.01 | Jan 11, 2022 | Windows Hyper-V Elevation of Privilege Vulnerability | ||
| CVE-2022-21855 | Cri | 0.59 | 9.0 | 0.01 | Jan 11, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2022-21846 | Cri | 0.59 | 9.0 | 0.01 | Jan 11, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2021-43882 | Cri | 0.59 | 9.0 | 0.02 | Dec 15, 2021 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2021-26443 | Cri | 0.59 | 9.0 | 0.02 | Nov 10, 2021 | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability | ||
| CVE-2021-26427 | Cri | 0.59 | 9.0 | 0.01 | Oct 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2021-34535 | Hig | 0.59 | 8.8 | 0.22 | Aug 12, 2021 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2021-34448 | Med | 0.59 | 6.8 | 0.40 | KEV | Jul 16, 2021 | Scripting Engine Memory Corruption Vulnerability | |
| CVE-2021-28483 | Cri | 0.59 | 9.0 | 0.01 | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2021-21118 | Hig | 0.59 | 8.8 | 0.17 | Feb 9, 2021 | Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | ||
| CVE-2020-17142 | Cri | 0.59 | 9.1 | 0.03 | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability | ||
| CVE-2020-1481 | Hig | 0.59 | 8.8 | 0.24 | Jul 14, 2020 | A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source code after opening a project, aka 'Visual Studio Code ESLint Extention Remote Code Execution Vulnerability'. |
- risk 0.59cvss 8.8epss 0.19
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
- risk 0.59cvss 8.8epss 0.19
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.59cvss 9.0epss 0.01
Azure Bot Service Elevation of Privilege Vulnerability
- risk 0.59cvss 9.1epss 0.01
Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.
- risk 0.59cvss 8.8epss 0.22
Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.
- risk 0.59cvss 9.1epss 0.01
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.59cvss 8.8epss 0.18
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.59cvss 9.1epss 0.01
Azure Portal Elevation of Privilege Vulnerability
- risk 0.59cvss 9.0epss 0.01
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
- risk 0.59cvss 9.1epss 0.02
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network
- risk 0.59cvss 7.2epss 0.02
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or…
- risk 0.59cvss 9.0epss 0.01
Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.24
A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.
- risk 0.59cvss 9.0epss 0.01
Windows Netlogon Elevation of Privilege Vulnerability
- risk 0.59cvss 9.0epss 0.01
Azure Stack Hub Elevation of Privilege Vulnerability
- risk 0.59cvss 9.1epss 0.02
Windows Network Virtualization Remote Code Execution Vulnerability
- risk 0.59cvss 9.1epss 0.02
Windows Network Virtualization Remote Code Execution Vulnerability
- risk 0.59cvss 9.1epss 0.02
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.
- risk 0.59cvss 9.0epss 0.01
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
- risk 0.59cvss 9.1epss 0.01
Microsoft Defender for IoT Elevation of Privilege Vulnerability
- risk 0.59cvss 9.0epss 0.02
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
- risk 0.59cvss 9.0epss 0.01
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
- risk 0.59cvss 9.0epss 0.01
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.20
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.59cvss 8.8epss 0.17
Windows Kerberos Security Feature Bypass Vulnerability
- risk 0.59cvss 9.0epss 0.03
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions…
- risk 0.59cvss 8.0epss 0.87
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.59cvss 8.8epss 0.25
Windows Scripting Engine Memory Corruption Vulnerability
- risk 0.59cvss 8.0epss 0.82
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.59cvss 8.1epss 0.84
Windows OLE Remote Code Execution Vulnerability
- risk 0.59cvss 7.8epss 0.65
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- risk 0.59cvss 5.4epss 0.76
Windows SmartScreen Security Feature Bypass Vulnerability
- risk 0.59cvss 7.8epss 0.67
Visual Studio Code Remote Code Execution Vulnerability
- risk 0.59cvss 8.1epss 0.80
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.26
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.19
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.17
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.59cvss 9.0epss 0.01
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.59cvss 9.0epss 0.01
Windows Hyper-V Elevation of Privilege Vulnerability
- risk 0.59cvss 9.0epss 0.01
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.59cvss 9.0epss 0.01
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.59cvss 9.0epss 0.02
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.59cvss 9.0epss 0.02
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
- risk 0.59cvss 9.0epss 0.01
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.22
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.59cvss 6.8epss 0.40
Scripting Engine Memory Corruption Vulnerability
- risk 0.59cvss 9.0epss 0.01
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.17
Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
- risk 0.59cvss 9.1epss 0.03
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.24
A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source code after opening a project, aka 'Visual Studio Code ESLint Extention Remote Code Execution Vulnerability'.
Page 17 of 314