VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2025-21225MedJan 14, 2025
    risk 0.38cvss 5.9epss 0.02

    Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

  • CVE-2024-38264MedNov 12, 2024
    risk 0.38cvss 5.9epss 0.01

    Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability

  • CVE-2024-49023MedOct 18, 2024
    risk 0.38cvss 5.9epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2024-43587MedOct 17, 2024
    risk 0.38cvss 5.9epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2024-37985MedSep 17, 2024
    risk 0.38cvss 5.9epss 0.01

    Windows Kernel Information Disclosure Vulnerability

  • CVE-2024-43472MedAug 16, 2024
    risk 0.38cvss 5.8epss 0.00

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2024-38103MedJul 25, 2024
    risk 0.38cvss 5.9epss 0.00

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

  • CVE-2024-38099MedJul 9, 2024
    risk 0.38cvss 5.9epss 0.01

    Windows Remote Desktop Licensing Service Denial of Service Vulnerability

  • CVE-2024-30046MedMay 14, 2024
    risk 0.38cvss 5.9epss 0.02

    Visual Studio Denial of Service Vulnerability

  • CVE-2024-21344MedFeb 13, 2024
    risk 0.38cvss 5.9epss 0.02

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

  • CVE-2024-21343MedFeb 13, 2024
    risk 0.38cvss 5.9epss 0.02

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

  • CVE-2024-21306MedJan 9, 2024
    risk 0.38cvss 5.7epss 0.06

    Microsoft Bluetooth Driver Spoofing Vulnerability

  • CVE-2022-35747MedMay 31, 2023
    risk 0.38cvss 5.9epss 0.02

    Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability

  • CVE-2023-24900MedMay 9, 2023
    risk 0.38cvss 5.9epss 0.01

    Windows NTLM Security Support Provider Information Disclosure Vulnerability

  • CVE-2022-41116MedNov 9, 2022
    risk 0.38cvss 5.9epss 0.01

    Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

  • CVE-2022-41090MedNov 9, 2022
    risk 0.38cvss 5.9epss 0.01

    Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

  • CVE-2022-41064MedNov 9, 2022
    risk 0.38cvss 5.8epss 0.01

    .NET Framework Information Disclosure Vulnerability

  • CVE-2022-37965MedOct 11, 2022
    risk 0.38cvss 5.9epss 0.02

    Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

  • CVE-2022-23278MedMar 9, 2022
    risk 0.38cvss 5.9epss 0.02

    Microsoft Defender for Endpoint Spoofing Vulnerability

  • CVE-2022-23255MedFeb 9, 2022
    risk 0.38cvss 5.9epss 0.01

    Microsoft OneDrive for Android Security Feature Bypass Vulnerability

  • CVE-2020-1152MedSep 11, 2020
    risk 0.38cvss 5.8epss 0.01

    An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. To exploit the vulnerability, an attacker would have to log…

  • CVE-2019-1262MedSep 11, 2019
    risk 0.38cvss 5.4epss 0.03

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.

  • CVE-2019-0723MedAug 14, 2019
    risk 0.38cvss 5.8epss 0.05

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To…

  • CVE-2019-0718MedAug 14, 2019
    risk 0.38cvss 5.8epss 0.05

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To…

  • CVE-2019-0717MedAug 14, 2019
    risk 0.38cvss 5.8epss 0.05

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To…

  • CVE-2019-0716MedAug 14, 2019
    risk 0.38cvss 5.8epss 0.04

    A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected…

  • CVE-2019-0715MedAug 14, 2019
    risk 0.38cvss 5.8epss 0.05

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To…

  • CVE-2019-0714MedAug 14, 2019
    risk 0.38cvss 5.8epss 0.05

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To…

  • CVE-2019-1040MedJun 12, 2019
    risk 0.38cvss 5.3epss 0.48

    A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security…

  • CVE-2019-0612MedApr 8, 2019
    risk 0.38cvss 5.3epss 0.11

    A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By itself, this bypass vulnerability does not allow arbitrary code execution, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.

  • CVE-2018-0885MedMar 14, 2018
    risk 0.38cvss 5.8epss 0.05

    The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows a denial of service vulnerability due to…

  • CVE-2017-11830MedNov 15, 2017
    risk 0.38cvss 5.3epss 0.03

    Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsigned file appear to be signed, due to a security feature bypass, aka "Device Guard Security Feature Bypass Vulnerability".

  • CVE-2017-0194MedApr 12, 2017
    risk 0.38cvss 5.5epss 0.26

    Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."

  • CVE-2017-0191MedApr 12, 2017
    risk 0.38cvss 5.8epss 0.05

    A denial of service vulnerability exists in the way that Windows 7, Windows 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 handles objects in memory. An attacker who successfully exploited the vulnerability could…

  • CVE-2017-0186MedApr 12, 2017
    risk 0.38cvss 5.8epss 0.05

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating…

  • CVE-2017-0185MedApr 12, 2017
    risk 0.38cvss 5.8epss 0.06

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating…

  • CVE-2017-0183MedApr 12, 2017
    risk 0.38cvss 5.8epss 0.04

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating…

  • CVE-2017-0182MedApr 12, 2017
    risk 0.38cvss 5.8epss 0.04

    A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating…

  • CVE-2017-0179MedApr 12, 2017
    risk 0.38cvss 5.8epss 0.04

    A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service…

  • CVE-2017-0168MedApr 12, 2017
    risk 0.38cvss 5.8epss 0.06

    An information disclosure vulnerability exists when the Windows Hyper-V Network Switch running on a Windows 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, or Windows Server 2012 R2 host operating system fails to properly validate input from an…

  • CVE-2017-0105MedMar 17, 2017
    risk 0.38cvss 5.5epss 0.30

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from out-of-bound memory via a…

  • CVE-2016-3263MedOct 14, 2016
    risk 0.38cvss 5.5epss 0.32

    Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for…

  • CVE-2016-3262MedOct 14, 2016
    risk 0.38cvss 5.5epss 0.32

    Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for…

  • CVE-2016-3315MedAug 9, 2016
    risk 0.38cvss 5.5epss 0.30

    Microsoft OneNote 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to obtain sensitive information via a crafted OneNote file, aka "Microsoft OneNote Information Disclosure Vulnerability."

  • CVE-2016-3234MedJun 16, 2016
    risk 0.38cvss 5.5epss 0.24

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1…

  • CVE-2016-3215MedJun 16, 2016
    risk 0.38cvss 5.5epss 0.34

    Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability…

  • CVE-2016-0028MedJun 16, 2016
    risk 0.38cvss 5.5epss 0.23

    Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML…

  • CVE-2026-42915MedJun 9, 2026
    risk 0.37cvss 5.7epss 0.00

    Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service over an adjacent network.

  • CVE-2026-23670MedApr 14, 2026
    risk 0.37cvss 5.7epss 0.00

    Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-23653MedApr 14, 2026
    risk 0.37cvss 5.7epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.

Page 181 of 314