VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2023-28249MedApr 11, 2023
    risk 0.40cvss 6.2epss 0.01

    Windows Boot Manager Security Feature Bypass Vulnerability

  • CVE-2023-24935MedApr 11, 2023
    risk 0.40cvss 6.1epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2023-21697MedFeb 14, 2023
    risk 0.40cvss 6.2epss 0.01

    Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability

  • CVE-2022-37967HigNov 9, 2022
    risk 0.40cvss 7.2epss 0.05

    Windows Kerberos Elevation of Privilege Vulnerability

  • CVE-2022-35797MedAug 9, 2022
    risk 0.40cvss 6.1epss 0.01

    Windows Hello Security Feature Bypass Vulnerability

  • CVE-2022-35776MedAug 9, 2022
    risk 0.40cvss 6.2epss 0.01

    Azure Site Recovery Denial of Service Vulnerability

  • CVE-2022-22048MedJul 12, 2022
    risk 0.40cvss 6.1epss 0.01

    BitLocker Security Feature Bypass Vulnerability

  • CVE-2022-24526MedMar 9, 2022
    risk 0.40cvss 6.1epss 0.02

    Visual Studio Code Spoofing Vulnerability

  • CVE-2022-21970MedJan 11, 2022
    risk 0.40cvss 6.1epss 0.03

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2022-21954MedJan 11, 2022
    risk 0.40cvss 6.1epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2022-21839MedJan 11, 2022
    risk 0.40cvss 6.1epss 0.02

    Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability

  • CVE-2021-41368MedNov 10, 2021
    risk 0.40cvss 6.1epss 0.05

    Microsoft Access Remote Code Execution Vulnerability

  • CVE-2021-38657MedSep 15, 2021
    risk 0.40cvss 6.1epss 0.01

    Microsoft Office Graphics Component Information Disclosure Vulnerability

  • CVE-2021-38642MedSep 2, 2021
    risk 0.40cvss 6.1epss 0.01

    Microsoft Edge for iOS Spoofing Vulnerability

  • CVE-2021-38641MedSep 2, 2021
    risk 0.40cvss 6.1epss 0.01

    Microsoft Edge for Android Spoofing Vulnerability

  • CVE-2021-26436MedSep 2, 2021
    risk 0.40cvss 6.1epss 0.03

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2021-33765MedJul 14, 2021
    risk 0.40cvss 6.2epss 0.01

    Windows Installer Spoofing Vulnerability

  • CVE-2021-31961MedJul 14, 2021
    risk 0.40cvss 6.1epss 0.01

    Windows InstallService Elevation of Privilege Vulnerability

  • CVE-2021-28461MedMay 11, 2021
    risk 0.40cvss 6.1epss 0.01

    Dynamics Finance and Operations Cross-site Scripting Vulnerability

  • CVE-2021-28459MedApr 13, 2021
    risk 0.40cvss 6.1epss 0.02

    Azure DevOps Server Spoofing Vulnerability

  • CVE-2021-26413MedApr 13, 2021
    risk 0.40cvss 6.2epss 0.01

    Windows Installer Spoofing Vulnerability

  • CVE-2021-27074MedMar 11, 2021
    risk 0.40cvss 6.2epss 0.01

    Azure Sphere Unsigned Code Execution Vulnerability

  • CVE-2021-26892MedMar 11, 2021
    risk 0.40cvss 6.2epss 0.01

    Windows Extensible Firmware Interface Security Feature Bypass Vulnerability

  • CVE-2021-26886MedMar 11, 2021
    risk 0.40cvss 6.1epss 0.01

    User Profile Service Denial of Service Vulnerability

  • CVE-2021-1724MedFeb 25, 2021
    risk 0.40cvss 6.1epss 0.01

    Microsoft Dynamics Business Central Cross-site Scripting Vulnerability

  • CVE-2020-16990MedNov 11, 2020
    risk 0.40cvss 6.2epss 0.01

    Azure Sphere Information Disclosure Vulnerability

  • CVE-2020-16986MedNov 11, 2020
    risk 0.40cvss 6.2epss 0.01

    Azure Sphere Denial of Service Vulnerability

  • CVE-2020-16985MedNov 11, 2020
    risk 0.40cvss 6.2epss 0.02

    Azure Sphere Information Disclosure Vulnerability

  • CVE-2020-16982MedNov 11, 2020
    risk 0.40cvss 6.1epss 0.01

    Azure Sphere Unsigned Code Execution Vulnerability

  • CVE-2020-16981MedNov 11, 2020
    risk 0.40cvss 6.1epss 0.01

    Azure Sphere Elevation of Privilege Vulnerability

  • CVE-2020-26505MedNov 5, 2020
    risk 0.40cvss 6.1epss 0.01

    A Stored Cross-Site Scripting (XSS) vulnerability in the “Marmind” web application with version 4.1.141.0 allows an attacker to inject code that will later be executed by legitimate users when they open the assets containing the JavaScript code. This would allow an attacker…

  • CVE-2020-1598MedSep 11, 2020
    risk 0.40cvss 6.1epss 0.01

    An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could…

  • CVE-2020-1506MedSep 11, 2020
    risk 0.40cvss 6.1epss 0.02

    An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. There are multiple ways an attacker could exploit the…

  • CVE-2020-1442MedJul 14, 2020
    risk 0.40cvss 6.1epss 0.02

    A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, aka 'Office Web Apps XSS Vulnerability'.

  • CVE-2020-1327MedJun 9, 2020
    risk 0.40cvss 6.1epss 0.02

    A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.

  • CVE-2020-1323MedJun 9, 2020
    risk 0.40cvss 6.1epss 0.02

    An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.

  • CVE-2020-1220MedJun 9, 2020
    risk 0.40cvss 6.1epss 0.02

    A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.

  • CVE-2020-1106MedMay 21, 2020
    risk 0.40cvss 6.1epss 0.04

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an…

  • CVE-2020-1050MedApr 15, 2020
    risk 0.40cvss 6.1epss 0.02

    A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This CVE ID is unique…

  • CVE-2009-5159MedMar 13, 2020
    risk 0.40cvss 6.1epss 0.03

    Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.

  • CVE-2019-1486MedDec 10, 2019
    risk 0.40cvss 6.1epss 0.01

    A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'.

  • CVE-2019-1470MedDec 10, 2019
    risk 0.40cvss 6.0epss 0.06

    An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.

  • CVE-2019-1332MedDec 10, 2019
    risk 0.40cvss 6.1epss 0.07

    A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.

  • CVE-2019-1399MedNov 12, 2019
    risk 0.40cvss 6.2epss 0.02

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309,…

  • CVE-2019-1266MedSep 11, 2019
    risk 0.40cvss 6.1epss 0.02

    A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'.

  • CVE-2019-0928MedSep 11, 2019
    risk 0.40cvss 6.2epss 0.02

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.

  • CVE-2019-1125MedSep 3, 2019
    risk 0.40cvss 5.6epss 0.05

    An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would…

  • CVE-2019-1075MedJul 15, 2019
    risk 0.40cvss 6.1epss 0.03

    A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.

  • CVE-2019-0874MedApr 9, 2019
    risk 0.40cvss 6.1epss 0.02

    A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.

  • CVE-2019-0871MedApr 9, 2019
    risk 0.40cvss 6.1epss 0.02

    A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866,…

Page 177 of 314