VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2015-6117MedJan 13, 2016
    risk 0.40cvss 6.1epss 0.07

    Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature…

  • CVE-2012-1872MedJun 12, 2012
    risk 0.40cvss 6.1epss 0.06

    Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability."

  • CVE-2007-2237MedJun 6, 2007
    risk 0.40cvss 5.5epss 0.15

    Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.

  • CVE-2026-62897HigAug 11, 2026
    risk 0.39cvss 7.0epss 0.00

    Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

  • CVE-2026-59867HigJul 16, 2026
    risk 0.39cvss 7.1epss 0.02

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-controlled or attacker-influenced…

  • CVE-2026-59863HigJul 16, 2026
    risk 0.39cvss epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing…

  • CVE-2026-44641HigMay 15, 2026
    risk 0.39cvss 7.1epss 0.00

    Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM normalizes marketplace plugins by copying plugin components referenced in plugin.json into .apm/. The manifest fields agents, skills, commands, and hooks are…

  • CVE-2026-44503HigMay 14, 2026
    risk 0.39cvss epss 0.01

    The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme. Only the Authorization header is removed;…

  • CVE-2025-21195MedJul 8, 2025
    risk 0.39cvss 6.0epss 0.00

    Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27735MedApr 8, 2025
    risk 0.39cvss 6.0epss 0.00

    Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

  • CVE-2025-21350MedFeb 11, 2025
    risk 0.39cvss 5.9epss 0.02

    Windows Kerberos Denial of Service Vulnerability

  • CVE-2025-21347MedFeb 11, 2025
    risk 0.39cvss 6.0epss 0.01

    Windows Deployment Services Denial of Service Vulnerability

  • CVE-2025-21188MedFeb 11, 2025
    risk 0.39cvss 6.0epss 0.01

    Azure Network Watcher VM Extension Elevation of Privilege Vulnerability

  • CVE-2024-20685MedApr 9, 2024
    risk 0.39cvss 5.9epss 0.06

    Azure Private 5G Core Denial of Service Vulnerability

  • CVE-2024-21643HigJan 10, 2024
    risk 0.39cvss 7.1epss 0.02

    IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable.…

  • CVE-2023-29337HigJun 14, 2023
    risk 0.39cvss 7.1epss 0.01

    NuGet Client Remote Code Execution Vulnerability

  • CVE-2022-37985MedOct 11, 2022
    risk 0.39cvss 5.5epss 0.39

    Windows Graphics Component Information Disclosure Vulnerability

  • CVE-2022-34716MedAug 9, 2022
    risk 0.39cvss 5.9epss 0.02

    .NET Spoofing Vulnerability

  • CVE-2022-34709MedAug 9, 2022
    risk 0.39cvss 6.0epss 0.01

    Windows Defender Credential Guard Security Feature Bypass Vulnerability

  • CVE-2022-22028MedJul 12, 2022
    risk 0.39cvss 5.9epss 0.02

    Windows Network File System Information Disclosure Vulnerability

  • CVE-2022-24765MedApr 12, 2022
    risk 0.39cvss 6.0epss 0.01

    Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, which would be…

  • CVE-2021-42300MedNov 10, 2021
    risk 0.39cvss 6.0epss 0.01

    Azure Sphere Tampering Vulnerability

  • CVE-2021-41355MedOct 13, 2021
    risk 0.39cvss 5.7epss 0.20

    .NET Core and Visual Studio Information Disclosure Vulnerability

  • CVE-2021-36928MedAug 26, 2021
    risk 0.39cvss 6.0epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2021-26430MedAug 12, 2021
    risk 0.39cvss 6.0epss 0.01

    Azure Sphere Denial of Service Vulnerability

  • CVE-2021-33764MedJul 14, 2021
    risk 0.39cvss 5.9epss 0.04

    Windows Key Distribution Center Information Disclosure Vulnerability

  • CVE-2021-31957MedJun 8, 2021
    risk 0.39cvss 5.9epss 0.05

    ASP.NET Core Denial of Service Vulnerability

  • CVE-2020-1343MedJun 9, 2020
    risk 0.39cvss 5.9epss 0.03

    An information disclosure vulnerability exists in Visual Studio Code Live Share Extension when it exposes tokens in plain text, aka 'Visual Studio Code Live Share Information Disclosure Vulnerability'.

  • CVE-2020-0751MedFeb 11, 2020
    risk 0.39cvss 6.0epss 0.01

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system,…

  • CVE-2020-0617MedJan 14, 2020
    risk 0.39cvss 6.0epss 0.01

    A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Hyper-V Denial of Service Vulnerability'.

  • CVE-2019-1345MedOct 10, 2019
    risk 0.39cvss 5.5epss 0.03

    An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1334.

  • CVE-2019-1344MedOct 10, 2019
    risk 0.39cvss 5.5epss 0.03

    An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memory, aka 'Windows Code Integrity Module Information Disclosure Vulnerability'.

  • CVE-2019-1338MedOct 10, 2019
    risk 0.39cvss 5.9epss 0.04

    A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLMv2 protection if a client is also sending LMv2 responses, aka 'Windows NTLM Security Feature Bypass Vulnerability'.

  • CVE-2019-1318MedOct 10, 2019
    risk 0.39cvss 5.9epss 0.04

    A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.

  • CVE-2019-1231MedSep 11, 2019
    risk 0.39cvss 5.9epss 0.02

    An information disclosure vulnerability exists in the way Rome SDK handles server SSL/TLS certificate validation, aka 'Rome SDK Information Disclosure Vulnerability'.

  • CVE-2019-1153MedAug 14, 2019
    risk 0.39cvss 5.5epss 0.03

    An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this…

  • CVE-2019-1148MedAug 14, 2019
    risk 0.39cvss 5.5epss 0.03

    An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this…

  • CVE-2019-1029MedJun 12, 2019
    risk 0.39cvss 5.9epss 0.05

    A denial of service vulnerability exists in Skype for Business. An attacker who successfully exploited the vulnerability could cause Skype for Business to stop responding. Note that the denial of service would not allow an attacker to execute code or to elevate the attacker's…

  • CVE-2019-1008MedMay 16, 2019
    risk 0.39cvss 5.9epss 0.03

    A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'.

  • CVE-2019-0932MedMay 16, 2019
    risk 0.39cvss 5.9epss 0.05

    An information disclosure vulnerability exists in Skype for Android, aka 'Skype for Android Information Disclosure Vulnerability'.

  • CVE-2019-0796MedApr 9, 2019
    risk 0.39cvss 5.5epss 0.04

    An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0805, CVE-2019-0836, CVE-2019-0841.

  • CVE-2019-0683MedApr 9, 2019
    risk 0.39cvss 5.9epss 0.03

    An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.

  • CVE-2019-0657MedMar 5, 2019
    risk 0.39cvss 5.9epss 0.05

    A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.

  • CVE-2019-0641MedMar 5, 2019
    risk 0.39cvss 5.9epss 0.03

    A security feature bypass vulnerability exists in Microsoft Edge handles whitelisting, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.

  • CVE-2018-8546MedNov 14, 2018
    risk 0.39cvss 5.9epss 0.05

    A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype.

  • CVE-2018-8444MedSep 13, 2018
    risk 0.39cvss 5.9epss 0.06

    An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka "Windows SMB Information Disclosure Vulnerability." This affects Windows Server 2012, Windows 10, Windows 8.1, Windows RT 8.1,…

  • CVE-2018-8304MedJul 11, 2018
    risk 0.39cvss 5.9epss 0.12

    A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008,…

  • CVE-2017-17689MedMay 16, 2018
    risk 0.39cvss 5.9epss 0.04

    The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

  • CVE-2017-17688MedMay 16, 2018
    risk 0.39cvss 5.9epss 0.06

    The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature…

  • CVE-2018-0975MedApr 12, 2018
    risk 0.39cvss 5.5epss 0.03

    An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows…

Page 179 of 314