VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2026-21529MedFeb 10, 2026
    risk 0.37cvss 5.7epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.

  • CVE-2025-53719MedAug 12, 2025
    risk 0.37cvss 5.7epss 0.01

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

  • CVE-2025-53153MedAug 12, 2025
    risk 0.37cvss 5.7epss 0.01

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

  • CVE-2025-53148MedAug 12, 2025
    risk 0.37cvss 5.7epss 0.01

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

  • CVE-2025-53138MedAug 12, 2025
    risk 0.37cvss 5.7epss 0.01

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

  • CVE-2025-50157MedAug 12, 2025
    risk 0.37cvss 5.7epss 0.01

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

  • CVE-2025-50156MedAug 12, 2025
    risk 0.37cvss 5.7epss 0.01

    Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

  • CVE-2025-49722MedJul 8, 2025
    risk 0.37cvss 5.7epss 0.01

    Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network.

  • CVE-2025-48002MedJul 8, 2025
    risk 0.37cvss 5.7epss 0.01

    Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network.

  • CVE-2025-29974MedMay 13, 2025
    risk 0.37cvss 5.7epss 0.01

    Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.

  • CVE-2025-29817MedApr 15, 2025
    risk 0.37cvss 5.7epss 0.01

    Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.

  • CVE-2024-43604MedOct 8, 2024
    risk 0.37cvss 5.7epss 0.01

    Outlook for Android Elevation of Privilege Vulnerability

  • CVE-2024-35263MedJun 11, 2024
    risk 0.37cvss 5.7epss 0.02

    Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

  • CVE-2024-26209MedApr 9, 2024
    risk 0.37cvss 5.5epss 0.15

    Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

  • CVE-2024-26160MedMar 12, 2024
    risk 0.37cvss 5.5epss 0.11

    Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

  • CVE-2024-21430MedMar 12, 2024
    risk 0.37cvss 5.7epss 0.01

    Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability

  • CVE-2024-20695MedFeb 13, 2024
    risk 0.37cvss 5.7epss 0.01

    Skype for Business Information Disclosure Vulnerability

  • CVE-2024-20692MedJan 9, 2024
    risk 0.37cvss 5.7epss 0.01

    Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

  • CVE-2023-20588MedAug 8, 2023
    risk 0.37cvss 5.5epss 0.11

    A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. 

  • CVE-2023-28261MedApr 27, 2023
    risk 0.37cvss 5.7epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2023-21693MedFeb 14, 2023
    risk 0.37cvss 5.7epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

  • CVE-2022-29799MedSep 21, 2022
    risk 0.37cvss 5.5epss 0.12

    A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base…

  • CVE-2022-30223MedJul 12, 2022
    risk 0.37cvss 5.7epss 0.01

    Windows Hyper-V Information Disclosure Vulnerability

  • CVE-2022-22711MedJul 12, 2022
    risk 0.37cvss 5.7epss 0.01

    Windows BitLocker Information Disclosure Vulnerability

  • CVE-2021-42288MedNov 10, 2021
    risk 0.37cvss 5.7epss 0.01

    Windows Hello Security Feature Bypass Vulnerability

  • CVE-2021-38632MedSep 15, 2021
    risk 0.37cvss 5.7epss 0.01

    Windows BitLocker Security Feature Bypass Vulnerability

  • CVE-2021-34466MedJul 16, 2021
    risk 0.37cvss 5.7epss 0.01

    Windows Hello Security Feature Bypass Vulnerability

  • CVE-2021-31965MedJun 8, 2021
    risk 0.37cvss 5.7epss 0.05

    Microsoft SharePoint Server Information Disclosure Vulnerability

  • CVE-2021-31178MedMay 11, 2021
    risk 0.37cvss 5.5epss 0.16

    Microsoft Office Information Disclosure Vulnerability

  • CVE-2021-28444MedApr 13, 2021
    risk 0.37cvss 5.7epss 0.02

    Windows Hyper-V Security Feature Bypass Vulnerability

  • CVE-2021-27079MedApr 13, 2021
    risk 0.37cvss 5.7epss 0.03

    Windows Media Photo Codec Information Disclosure Vulnerability

  • CVE-2021-24114MedFeb 25, 2021
    risk 0.37cvss 5.7epss 0.03

    Microsoft Teams iOS Information Disclosure Vulnerability

  • CVE-2021-1708MedJan 12, 2021
    risk 0.37cvss 5.7epss 0.03

    Windows GDI+ Information Disclosure Vulnerability

  • CVE-2020-10146MedDec 9, 2020
    risk 0.37cvss 5.7epss 0.02

    The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens and to possibly execute arbitrary commands. This…

  • CVE-2020-1599MedNov 11, 2020
    risk 0.37cvss 5.5epss 0.19

    Windows Spoofing Vulnerability

  • CVE-2020-17083MedNov 11, 2020
    risk 0.37cvss 5.5epss 0.12

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2020-16983MedNov 11, 2020
    risk 0.37cvss 5.7epss 0.01

    Azure Sphere Tampering Vulnerability

  • CVE-2020-15707MedJul 29, 2020
    risk 0.37cvss 5.7epss 0.02

    Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be…

  • CVE-2019-1171MedAug 14, 2019
    risk 0.37cvss 5.6epss 0.01

    An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log…

  • CVE-2019-0950MedMay 16, 2019
    risk 0.37cvss 5.7epss 0.02

    A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019-0951.

  • CVE-2019-0949MedMay 16, 2019
    risk 0.37cvss 5.7epss 0.02

    A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950, CVE-2019-0951.

  • CVE-2019-0540MedMar 5, 2019
    risk 0.37cvss 5.5epss 0.13

    A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.

  • CVE-2018-8472MedOct 10, 2018
    risk 0.37cvss 5.5epss 0.19

    An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows…

  • CVE-2018-8479MedSep 13, 2018
    risk 0.37cvss 5.6epss 0.02

    A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure IoT SDK Spoofing Vulnerability." This affects C SDK.

  • CVE-2018-8429MedSep 13, 2018
    risk 0.37cvss 5.5epss 0.12

    An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.

  • CVE-2018-8382MedAug 15, 2018
    risk 0.37cvss 5.5epss 0.12

    An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.

  • CVE-2018-8246MedJun 14, 2018
    risk 0.37cvss 5.5epss 0.18

    An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.

  • CVE-2018-8163MedMay 9, 2018
    risk 0.37cvss 5.5epss 0.13

    An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Excel.

  • CVE-2018-0941MedMar 14, 2018
    risk 0.37cvss 5.5epss 0.12

    Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how data is imported, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from…

  • CVE-2018-0888MedMar 14, 2018
    risk 0.37cvss 5.6epss 0.01

    The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an…

Page 182 of 314