VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2016-0084HigFeb 10, 2016
    risk 0.59cvss 8.8epss 0.17

    Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability."

  • CVE-2016-0072HigFeb 10, 2016
    risk 0.59cvss 8.8epss 0.20

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060,…

  • CVE-2016-0062HigFeb 10, 2016
    risk 0.59cvss 8.8epss 0.21

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."

  • CVE-2016-0061HigFeb 10, 2016
    risk 0.59cvss 8.8epss 0.21

    Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than…

  • CVE-2016-0060HigFeb 10, 2016
    risk 0.59cvss 8.8epss 0.27

    Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than…

  • CVE-2016-0024HigJan 13, 2016
    risk 0.59cvss 8.8epss 0.17

    The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Scripting Engine Memory Corruption Vulnerability."

  • CVE-2013-0006HigJan 9, 2013
    risk 0.59cvss 8.8epss 0.28

    Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."

  • CVE-2012-4775HigNov 14, 2012
    risk 0.59cvss 8.8epss 0.22

    Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site, aka "CTreeNode Use After Free Vulnerability."

  • CVE-2012-0175HigJul 10, 2012
    risk 0.59cvss 8.8epss 0.26

    The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted name for a (1) file or (2) directory, aka "Command…

  • CVE-2011-3406HigDec 14, 2011
    risk 0.59cvss 8.8epss 0.23

    Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold…

  • CVE-2011-0663HigApr 13, 2011
    risk 0.59cvss 8.8epss 0.26

    Multiple integer overflows in the Microsoft (1) JScript 5.6 through 5.8 and (2) VBScript 5.6 through 5.8 scripting engines allow remote attackers to execute arbitrary code via a crafted web page, aka "Scripting Memory Reallocation Vulnerability."

  • CVE-2009-1544HigAug 12, 2009
    risk 0.59cvss 8.8epss 0.21

    Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold,…

  • CVE-2026-73299CriAug 12, 2026
    risk 0.58cvss 10.0epss 0.01

    Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and…

  • CVE-2026-68820HigKEVAug 11, 2026
    risk 0.58cvss 7.0epss 0.06

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26030CriFeb 19, 2026
    risk 0.58cvss 9.9epss 0.04

    Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users should upgrade this…

  • CVE-2026-25592CriFeb 6, 2026
    risk 0.58cvss 9.9epss 0.02

    Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the SessionsPythonPlugin. The problem…

  • CVE-2025-54110HigSep 9, 2025
    risk 0.58cvss 8.8epss 0.04

    Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-53145HigAug 12, 2025
    risk 0.58cvss 8.8epss 0.06

    Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

  • CVE-2025-53144HigAug 12, 2025
    risk 0.58cvss 8.8epss 0.06

    Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.

  • CVE-2025-49724HigJul 8, 2025
    risk 0.58cvss 8.8epss 0.08

    Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network.

  • CVE-2025-47957HigJun 10, 2025
    risk 0.58cvss 8.4epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-47163HigJun 10, 2025
    risk 0.58cvss 8.8epss 0.15

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2025-29962HigMay 13, 2025
    risk 0.58cvss 8.8epss 0.14

    Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

  • CVE-2025-29794HigApr 8, 2025
    risk 0.58cvss 8.8epss 0.05

    Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2025-24983HigKEVMar 11, 2025
    risk 0.58cvss 7.0epss 0.01

    Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21391HigKEVFeb 11, 2025
    risk 0.58cvss 7.1epss 0.02

    Windows Storage Elevation of Privilege Vulnerability

  • CVE-2024-43573MedKEVOct 8, 2024
    risk 0.58cvss 6.5epss 0.44

    Windows MSHTML Platform Spoofing Vulnerability

  • CVE-2024-43532HigOct 8, 2024
    risk 0.58cvss 8.8epss 0.12

    Remote Registry Service Elevation of Privilege Vulnerability

  • CVE-2024-38106HigKEVAug 13, 2024
    risk 0.58cvss 7.0epss 0.06

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-38060HigJul 9, 2024
    risk 0.58cvss 8.8epss 0.16

    Windows Imaging Component Remote Code Execution Vulnerability

  • CVE-2024-30078HigJun 11, 2024
    risk 0.58cvss 8.8epss 0.05

    Windows Wi-Fi Driver Remote Code Execution Vulnerability

  • CVE-2024-26198HigMar 12, 2024
    risk 0.58cvss 8.8epss 0.07

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2024-21378HigFeb 13, 2024
    risk 0.58cvss 8.8epss 0.11

    Microsoft Outlook Remote Code Execution Vulnerability

  • CVE-2023-35641HigDec 12, 2023
    risk 0.58cvss 8.8epss 0.07

    Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

  • CVE-2023-35630HigDec 12, 2023
    risk 0.58cvss 8.8epss 0.06

    Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

  • CVE-2023-48315HigDec 5, 2023
    risk 0.58cvss 8.8epss 0.04

    Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions…

  • CVE-2023-36400HigNov 14, 2023
    risk 0.58cvss 8.8epss 0.04

    Windows HMAC Key Derivation Elevation of Privilege Vulnerability

  • CVE-2023-36052HigNov 14, 2023
    risk 0.58cvss 8.6epss 0.22

    Azure CLI REST Command Information Disclosure Vulnerability

  • CVE-2023-36039HigNov 14, 2023
    risk 0.58cvss 8.0epss 0.73

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2023-38148HigSep 12, 2023
    risk 0.58cvss 8.8epss 0.08

    Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

  • CVE-2023-36756HigSep 12, 2023
    risk 0.58cvss 8.0epss 0.75

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2023-36745HigSep 12, 2023
    risk 0.58cvss 8.0epss 0.81

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2023-38181HigAug 8, 2023
    risk 0.58cvss 8.8epss 0.11

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2023-33160HigJul 11, 2023
    risk 0.58cvss 8.8epss 0.04

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2023-28229HigKEVApr 11, 2023
    risk 0.58cvss 7.0epss 0.02

    Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

  • CVE-2023-21706HigFeb 14, 2023
    risk 0.58cvss 8.8epss 0.04

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-30165HigJun 15, 2022
    risk 0.58cvss 8.8epss 0.04

    Windows Kerberos Elevation of Privilege Vulnerability

  • CVE-2022-30157HigJun 15, 2022
    risk 0.58cvss 8.8epss 0.08

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-29108HigMay 10, 2022
    risk 0.58cvss 8.8epss 0.12

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-26927HigMay 10, 2022
    risk 0.58cvss 8.8epss 0.04

    Windows Graphics Component Remote Code Execution Vulnerability

Page 20 of 314