VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2026-32215MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2026-32214MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

  • CVE-2026-32212MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

  • CVE-2026-32181MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.

  • CVE-2026-32085MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.

  • CVE-2026-32084MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-32081MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-32079MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-27931MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

  • CVE-2026-27930MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

  • CVE-2026-20806MedApr 14, 2026
    risk 0.36cvss 5.5epss 0.00

    Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.

  • CVE-2026-26123MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.

  • CVE-2026-25186MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to disclose information locally.

  • CVE-2026-25180MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.

  • CVE-2026-24282MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

  • CVE-2026-2636MedFeb 25, 2026
    risk 0.36cvss 5.5epss 0.00

    This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. This condition forces a call to the KeBugCheckEx function, allowing an unprivileged user to trigger…

  • CVE-2026-21261MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-21258MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-21222MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2026-20939MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-20937MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-20932MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-20862MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

  • CVE-2026-20839MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

  • CVE-2026-20838MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2026-20835MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.

  • CVE-2026-20833MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.

  • CVE-2026-20829MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.

  • CVE-2026-20827MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.

  • CVE-2026-20824MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-20823MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-20819MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

  • CVE-2025-62224MedJan 7, 2026
    risk 0.36cvss 5.5epss 0.00

    User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network.

  • CVE-2025-62468MedDec 9, 2025
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

  • CVE-2025-62209MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.01

    Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

  • CVE-2025-62208MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.01

    Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

  • CVE-2025-60706MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.

  • CVE-2025-59513MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.

  • CVE-2025-59510MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.01

    Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.

  • CVE-2025-59509MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.01

    Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.

  • CVE-2025-59240MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2025-59260MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally.

  • CVE-2025-59253MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

  • CVE-2025-59229MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.

  • CVE-2025-59211MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.

  • CVE-2025-59209MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.

  • CVE-2025-59204MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally.

  • CVE-2025-59203MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.

  • CVE-2025-59197MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.

  • CVE-2025-59190MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.

Page 185 of 314