Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-21529 | Med | 0.37 | 5.7 | 0.01 | Feb 10, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2025-53719 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53153 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53148 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53138 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-50157 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-50156 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-49722 | Med | 0.37 | 5.7 | 0.01 | Jul 8, 2025 | Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network. | ||
| CVE-2025-48002 | Med | 0.37 | 5.7 | 0.01 | Jul 8, 2025 | Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network. | ||
| CVE-2025-29974 | Med | 0.37 | 5.7 | 0.01 | May 13, 2025 | Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2025-29817 | Med | 0.37 | 5.7 | 0.01 | Apr 15, 2025 | Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. | ||
| CVE-2024-43604 | Med | 0.37 | 5.7 | 0.01 | Oct 8, 2024 | Outlook for Android Elevation of Privilege Vulnerability | ||
| CVE-2024-35263 | Med | 0.37 | 5.7 | 0.02 | Jun 11, 2024 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | ||
| CVE-2024-26209 | Med | 0.37 | 5.5 | 0.15 | Apr 9, 2024 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | ||
| CVE-2024-26160 | Med | 0.37 | 5.5 | 0.11 | Mar 12, 2024 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | ||
| CVE-2024-21430 | Med | 0.37 | 5.7 | 0.01 | Mar 12, 2024 | Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability | ||
| CVE-2024-20695 | Med | 0.37 | 5.7 | 0.01 | Feb 13, 2024 | Skype for Business Information Disclosure Vulnerability | ||
| CVE-2024-20692 | Med | 0.37 | 5.7 | 0.01 | Jan 9, 2024 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | ||
| CVE-2023-20588 | Med | 0.37 | 5.5 | 0.11 | Aug 8, 2023 | A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. | ||
| CVE-2023-28261 | Med | 0.37 | 5.7 | 0.01 | Apr 27, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2023-21693 | Med | 0.37 | 5.7 | 0.01 | Feb 14, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2022-29799 | Med | 0.37 | 5.5 | 0.12 | Sep 21, 2022 | A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base… | ||
| CVE-2022-30223 | Med | 0.37 | 5.7 | 0.01 | Jul 12, 2022 | Windows Hyper-V Information Disclosure Vulnerability | ||
| CVE-2022-22711 | Med | 0.37 | 5.7 | 0.01 | Jul 12, 2022 | Windows BitLocker Information Disclosure Vulnerability | ||
| CVE-2021-42288 | Med | 0.37 | 5.7 | 0.01 | Nov 10, 2021 | Windows Hello Security Feature Bypass Vulnerability | ||
| CVE-2021-38632 | Med | 0.37 | 5.7 | 0.01 | Sep 15, 2021 | Windows BitLocker Security Feature Bypass Vulnerability | ||
| CVE-2021-34466 | Med | 0.37 | 5.7 | 0.01 | Jul 16, 2021 | Windows Hello Security Feature Bypass Vulnerability | ||
| CVE-2021-31965 | Med | 0.37 | 5.7 | 0.05 | Jun 8, 2021 | Microsoft SharePoint Server Information Disclosure Vulnerability | ||
| CVE-2021-31178 | Med | 0.37 | 5.5 | 0.16 | May 11, 2021 | Microsoft Office Information Disclosure Vulnerability | ||
| CVE-2021-28444 | Med | 0.37 | 5.7 | 0.02 | Apr 13, 2021 | Windows Hyper-V Security Feature Bypass Vulnerability | ||
| CVE-2021-27079 | Med | 0.37 | 5.7 | 0.03 | Apr 13, 2021 | Windows Media Photo Codec Information Disclosure Vulnerability | ||
| CVE-2021-24114 | Med | 0.37 | 5.7 | 0.03 | Feb 25, 2021 | Microsoft Teams iOS Information Disclosure Vulnerability | ||
| CVE-2021-1708 | Med | 0.37 | 5.7 | 0.03 | Jan 12, 2021 | Windows GDI+ Information Disclosure Vulnerability | ||
| CVE-2020-10146 | Med | 0.37 | 5.7 | 0.02 | Dec 9, 2020 | The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens and to possibly execute arbitrary commands. This… | ||
| CVE-2020-1599 | Med | 0.37 | 5.5 | 0.19 | Nov 11, 2020 | Windows Spoofing Vulnerability | ||
| CVE-2020-17083 | Med | 0.37 | 5.5 | 0.12 | Nov 11, 2020 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2020-16983 | Med | 0.37 | 5.7 | 0.01 | Nov 11, 2020 | Azure Sphere Tampering Vulnerability | ||
| CVE-2020-15707 | Med | 0.37 | 5.7 | 0.02 | Jul 29, 2020 | Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be… | ||
| CVE-2019-1171 | Med | 0.37 | 5.6 | 0.01 | Aug 14, 2019 | An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log… | ||
| CVE-2019-0950 | Med | 0.37 | 5.7 | 0.02 | May 16, 2019 | A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019-0951. | ||
| CVE-2019-0949 | Med | 0.37 | 5.7 | 0.02 | May 16, 2019 | A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950, CVE-2019-0951. | ||
| CVE-2019-0540 | Med | 0.37 | 5.5 | 0.13 | Mar 5, 2019 | A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'. | ||
| CVE-2018-8472 | Med | 0.37 | 5.5 | 0.19 | Oct 10, 2018 | An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows… | ||
| CVE-2018-8479 | Med | 0.37 | 5.6 | 0.02 | Sep 13, 2018 | A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure IoT SDK Spoofing Vulnerability." This affects C SDK. | ||
| CVE-2018-8429 | Med | 0.37 | 5.5 | 0.12 | Sep 13, 2018 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. | ||
| CVE-2018-8382 | Med | 0.37 | 5.5 | 0.12 | Aug 15, 2018 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. | ||
| CVE-2018-8246 | Med | 0.37 | 5.5 | 0.18 | Jun 14, 2018 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. | ||
| CVE-2018-8163 | Med | 0.37 | 5.5 | 0.13 | May 9, 2018 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Excel. | ||
| CVE-2018-0941 | Med | 0.37 | 5.5 | 0.12 | Mar 14, 2018 | Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how data is imported, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from… | ||
| CVE-2018-0888 | Med | 0.37 | 5.6 | 0.01 | Mar 14, 2018 | The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an… |
- risk 0.37cvss 5.7epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network.
- risk 0.37cvss 5.7epss 0.01
Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network.
- risk 0.37cvss 5.7epss 0.01
Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.37cvss 5.7epss 0.01
Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Outlook for Android Elevation of Privilege Vulnerability
- risk 0.37cvss 5.7epss 0.02
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
- risk 0.37cvss 5.5epss 0.15
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
- risk 0.37cvss 5.5epss 0.11
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability
- risk 0.37cvss 5.7epss 0.01
Skype for Business Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.01
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
- risk 0.37cvss 5.5epss 0.11
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.
- risk 0.37cvss 5.7epss 0.01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.37cvss 5.7epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.37cvss 5.5epss 0.12
A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base…
- risk 0.37cvss 5.7epss 0.01
Windows Hyper-V Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows BitLocker Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows Hello Security Feature Bypass Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows BitLocker Security Feature Bypass Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows Hello Security Feature Bypass Vulnerability
- risk 0.37cvss 5.7epss 0.05
Microsoft SharePoint Server Information Disclosure Vulnerability
- risk 0.37cvss 5.5epss 0.16
Microsoft Office Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.02
Windows Hyper-V Security Feature Bypass Vulnerability
- risk 0.37cvss 5.7epss 0.03
Windows Media Photo Codec Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.03
Microsoft Teams iOS Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.03
Windows GDI+ Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.02
The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens and to possibly execute arbitrary commands. This…
- risk 0.37cvss 5.5epss 0.19
Windows Spoofing Vulnerability
- risk 0.37cvss 5.5epss 0.12
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.37cvss 5.7epss 0.01
Azure Sphere Tampering Vulnerability
- risk 0.37cvss 5.7epss 0.02
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be…
- risk 0.37cvss 5.6epss 0.01
An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log…
- risk 0.37cvss 5.7epss 0.02
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019-0951.
- risk 0.37cvss 5.7epss 0.02
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950, CVE-2019-0951.
- risk 0.37cvss 5.5epss 0.13
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
- risk 0.37cvss 5.5epss 0.19
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows…
- risk 0.37cvss 5.6epss 0.02
A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, aka "Azure IoT SDK Spoofing Vulnerability." This affects C SDK.
- risk 0.37cvss 5.5epss 0.12
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.
- risk 0.37cvss 5.5epss 0.12
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.
- risk 0.37cvss 5.5epss 0.18
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.
- risk 0.37cvss 5.5epss 0.13
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Excel.
- risk 0.37cvss 5.5epss 0.12
Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how data is imported, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from…
- risk 0.37cvss 5.6epss 0.01
The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an…
Page 182 of 314