Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28249 | Med | 0.40 | 6.2 | 0.01 | Apr 11, 2023 | Windows Boot Manager Security Feature Bypass Vulnerability | ||
| CVE-2023-24935 | Med | 0.40 | 6.1 | 0.01 | Apr 11, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2023-21697 | Med | 0.40 | 6.2 | 0.01 | Feb 14, 2023 | Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | ||
| CVE-2022-37967 | Hig | 0.40 | 7.2 | 0.05 | Nov 9, 2022 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2022-35797 | Med | 0.40 | 6.1 | 0.01 | Aug 9, 2022 | Windows Hello Security Feature Bypass Vulnerability | ||
| CVE-2022-35776 | Med | 0.40 | 6.2 | 0.01 | Aug 9, 2022 | Azure Site Recovery Denial of Service Vulnerability | ||
| CVE-2022-22048 | Med | 0.40 | 6.1 | 0.01 | Jul 12, 2022 | BitLocker Security Feature Bypass Vulnerability | ||
| CVE-2022-24526 | Med | 0.40 | 6.1 | 0.02 | Mar 9, 2022 | Visual Studio Code Spoofing Vulnerability | ||
| CVE-2022-21970 | Med | 0.40 | 6.1 | 0.03 | Jan 11, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2022-21954 | Med | 0.40 | 6.1 | 0.01 | Jan 11, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2022-21839 | Med | 0.40 | 6.1 | 0.02 | Jan 11, 2022 | Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability | ||
| CVE-2021-41368 | Med | 0.40 | 6.1 | 0.05 | Nov 10, 2021 | Microsoft Access Remote Code Execution Vulnerability | ||
| CVE-2021-38657 | Med | 0.40 | 6.1 | 0.01 | Sep 15, 2021 | Microsoft Office Graphics Component Information Disclosure Vulnerability | ||
| CVE-2021-38642 | Med | 0.40 | 6.1 | 0.01 | Sep 2, 2021 | Microsoft Edge for iOS Spoofing Vulnerability | ||
| CVE-2021-38641 | Med | 0.40 | 6.1 | 0.01 | Sep 2, 2021 | Microsoft Edge for Android Spoofing Vulnerability | ||
| CVE-2021-26436 | Med | 0.40 | 6.1 | 0.03 | Sep 2, 2021 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2021-33765 | Med | 0.40 | 6.2 | 0.01 | Jul 14, 2021 | Windows Installer Spoofing Vulnerability | ||
| CVE-2021-31961 | Med | 0.40 | 6.1 | 0.01 | Jul 14, 2021 | Windows InstallService Elevation of Privilege Vulnerability | ||
| CVE-2021-28461 | Med | 0.40 | 6.1 | 0.01 | May 11, 2021 | Dynamics Finance and Operations Cross-site Scripting Vulnerability | ||
| CVE-2021-28459 | Med | 0.40 | 6.1 | 0.02 | Apr 13, 2021 | Azure DevOps Server Spoofing Vulnerability | ||
| CVE-2021-26413 | Med | 0.40 | 6.2 | 0.01 | Apr 13, 2021 | Windows Installer Spoofing Vulnerability | ||
| CVE-2021-27074 | Med | 0.40 | 6.2 | 0.01 | Mar 11, 2021 | Azure Sphere Unsigned Code Execution Vulnerability | ||
| CVE-2021-26892 | Med | 0.40 | 6.2 | 0.01 | Mar 11, 2021 | Windows Extensible Firmware Interface Security Feature Bypass Vulnerability | ||
| CVE-2021-26886 | Med | 0.40 | 6.1 | 0.01 | Mar 11, 2021 | User Profile Service Denial of Service Vulnerability | ||
| CVE-2021-1724 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2021 | Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | ||
| CVE-2020-16990 | Med | 0.40 | 6.2 | 0.01 | Nov 11, 2020 | Azure Sphere Information Disclosure Vulnerability | ||
| CVE-2020-16986 | Med | 0.40 | 6.2 | 0.01 | Nov 11, 2020 | Azure Sphere Denial of Service Vulnerability | ||
| CVE-2020-16985 | Med | 0.40 | 6.2 | 0.02 | Nov 11, 2020 | Azure Sphere Information Disclosure Vulnerability | ||
| CVE-2020-16982 | Med | 0.40 | 6.1 | 0.01 | Nov 11, 2020 | Azure Sphere Unsigned Code Execution Vulnerability | ||
| CVE-2020-16981 | Med | 0.40 | 6.1 | 0.01 | Nov 11, 2020 | Azure Sphere Elevation of Privilege Vulnerability | ||
| CVE-2020-26505 | Med | 0.40 | 6.1 | 0.01 | Nov 5, 2020 | A Stored Cross-Site Scripting (XSS) vulnerability in the “Marmind” web application with version 4.1.141.0 allows an attacker to inject code that will later be executed by legitimate users when they open the assets containing the JavaScript code. This would allow an attacker… | ||
| CVE-2020-1598 | Med | 0.40 | 6.1 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could… | ||
| CVE-2020-1506 | Med | 0.40 | 6.1 | 0.02 | Sep 11, 2020 | An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. There are multiple ways an attacker could exploit the… | ||
| CVE-2020-1442 | Med | 0.40 | 6.1 | 0.02 | Jul 14, 2020 | A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, aka 'Office Web Apps XSS Vulnerability'. | ||
| CVE-2020-1327 | Med | 0.40 | 6.1 | 0.02 | Jun 9, 2020 | A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'. | ||
| CVE-2020-1323 | Med | 0.40 | 6.1 | 0.02 | Jun 9, 2020 | An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'. | ||
| CVE-2020-1220 | Med | 0.40 | 6.1 | 0.02 | Jun 9, 2020 | A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'. | ||
| CVE-2020-1106 | Med | 0.40 | 6.1 | 0.04 | May 21, 2020 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an… | ||
| CVE-2020-1050 | Med | 0.40 | 6.1 | 0.02 | Apr 15, 2020 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This CVE ID is unique… | ||
| CVE-2009-5159 | Med | 0.40 | 6.1 | 0.03 | Mar 13, 2020 | Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment. | ||
| CVE-2019-1486 | Med | 0.40 | 6.1 | 0.01 | Dec 10, 2019 | A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'. | ||
| CVE-2019-1470 | Med | 0.40 | 6.0 | 0.06 | Dec 10, 2019 | An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'. | ||
| CVE-2019-1332 | Med | 0.40 | 6.1 | 0.07 | Dec 10, 2019 | A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'. | ||
| CVE-2019-1399 | Med | 0.40 | 6.2 | 0.02 | Nov 12, 2019 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309,… | ||
| CVE-2019-1266 | Med | 0.40 | 6.1 | 0.02 | Sep 11, 2019 | A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. | ||
| CVE-2019-0928 | Med | 0.40 | 6.2 | 0.02 | Sep 11, 2019 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. | ||
| CVE-2019-1125 | Med | 0.40 | 5.6 | 0.05 | Sep 3, 2019 | An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would… | ||
| CVE-2019-1075 | Med | 0.40 | 6.1 | 0.03 | Jul 15, 2019 | A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. | ||
| CVE-2019-0874 | Med | 0.40 | 6.1 | 0.02 | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. | ||
| CVE-2019-0871 | Med | 0.40 | 6.1 | 0.02 | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866,… |
- risk 0.40cvss 6.2epss 0.01
Windows Boot Manager Security Feature Bypass Vulnerability
- risk 0.40cvss 6.1epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.40cvss 6.2epss 0.01
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
- risk 0.40cvss 7.2epss 0.05
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.40cvss 6.1epss 0.01
Windows Hello Security Feature Bypass Vulnerability
- risk 0.40cvss 6.2epss 0.01
Azure Site Recovery Denial of Service Vulnerability
- risk 0.40cvss 6.1epss 0.01
BitLocker Security Feature Bypass Vulnerability
- risk 0.40cvss 6.1epss 0.02
Visual Studio Code Spoofing Vulnerability
- risk 0.40cvss 6.1epss 0.03
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.40cvss 6.1epss 0.01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.40cvss 6.1epss 0.02
Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability
- risk 0.40cvss 6.1epss 0.05
Microsoft Access Remote Code Execution Vulnerability
- risk 0.40cvss 6.1epss 0.01
Microsoft Office Graphics Component Information Disclosure Vulnerability
- risk 0.40cvss 6.1epss 0.01
Microsoft Edge for iOS Spoofing Vulnerability
- risk 0.40cvss 6.1epss 0.01
Microsoft Edge for Android Spoofing Vulnerability
- risk 0.40cvss 6.1epss 0.03
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.40cvss 6.2epss 0.01
Windows Installer Spoofing Vulnerability
- risk 0.40cvss 6.1epss 0.01
Windows InstallService Elevation of Privilege Vulnerability
- risk 0.40cvss 6.1epss 0.01
Dynamics Finance and Operations Cross-site Scripting Vulnerability
- risk 0.40cvss 6.1epss 0.02
Azure DevOps Server Spoofing Vulnerability
- risk 0.40cvss 6.2epss 0.01
Windows Installer Spoofing Vulnerability
- risk 0.40cvss 6.2epss 0.01
Azure Sphere Unsigned Code Execution Vulnerability
- risk 0.40cvss 6.2epss 0.01
Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
- risk 0.40cvss 6.1epss 0.01
User Profile Service Denial of Service Vulnerability
- risk 0.40cvss 6.1epss 0.01
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
- risk 0.40cvss 6.2epss 0.01
Azure Sphere Information Disclosure Vulnerability
- risk 0.40cvss 6.2epss 0.01
Azure Sphere Denial of Service Vulnerability
- risk 0.40cvss 6.2epss 0.02
Azure Sphere Information Disclosure Vulnerability
- risk 0.40cvss 6.1epss 0.01
Azure Sphere Unsigned Code Execution Vulnerability
- risk 0.40cvss 6.1epss 0.01
Azure Sphere Elevation of Privilege Vulnerability
- risk 0.40cvss 6.1epss 0.01
A Stored Cross-Site Scripting (XSS) vulnerability in the “Marmind” web application with version 4.1.141.0 allows an attacker to inject code that will later be executed by legitimate users when they open the assets containing the JavaScript code. This would allow an attacker…
- risk 0.40cvss 6.1epss 0.01
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could…
- risk 0.40cvss 6.1epss 0.02
An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. There are multiple ways an attacker could exploit the…
- risk 0.40cvss 6.1epss 0.02
A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, aka 'Office Web Apps XSS Vulnerability'.
- risk 0.40cvss 6.1epss 0.02
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.
- risk 0.40cvss 6.1epss 0.02
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.
- risk 0.40cvss 6.1epss 0.02
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
- risk 0.40cvss 6.1epss 0.04
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an…
- risk 0.40cvss 6.1epss 0.02
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This CVE ID is unique…
- risk 0.40cvss 6.1epss 0.03
Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
- risk 0.40cvss 6.1epss 0.01
A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'.
- risk 0.40cvss 6.0epss 0.06
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
- risk 0.40cvss 6.1epss 0.07
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.
- risk 0.40cvss 6.2epss 0.02
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309,…
- risk 0.40cvss 6.1epss 0.02
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'.
- risk 0.40cvss 6.2epss 0.02
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
- risk 0.40cvss 5.6epss 0.05
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would…
- risk 0.40cvss 6.1epss 0.03
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
- risk 0.40cvss 6.1epss 0.02
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
- risk 0.40cvss 6.1epss 0.02
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866,…
Page 177 of 314