Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23270 | Hig | 0.58 | 8.1 | 0.70 | May 10, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-21984 | Hig | 0.58 | 8.8 | 0.05 | Feb 9, 2022 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2022-21919 | Hig | 0.58 | 7.0 | 0.03 | KEV | Jan 11, 2022 | Windows User Profile Service Elevation of Privilege Vulnerability | |
| CVE-2021-38666 | Hig | 0.58 | 8.8 | 0.14 | Nov 10, 2021 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2021-38649 | Hig | 0.58 | 7.0 | 0.03 | KEV | Sep 15, 2021 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| CVE-2021-36965 | Hig | 0.58 | 8.8 | 0.05 | Sep 15, 2021 | Windows WLAN AutoConfig Service Remote Code Execution Vulnerability | ||
| CVE-2021-30624 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30624 Use after free in Autofill | ||
| CVE-2021-30623 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30623 Use after free in Bookmarks | ||
| CVE-2021-30622 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30622 Use after free in WebApp Installs | ||
| CVE-2021-30620 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink | ||
| CVE-2021-30618 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30618 Inappropriate implementation in DevTools | ||
| CVE-2021-30616 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30616 Use after free in Media | ||
| CVE-2021-30614 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip | ||
| CVE-2021-30613 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30613 Use after free in Base internals | ||
| CVE-2021-30610 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30610 Use after free in Extensions API | ||
| CVE-2021-30609 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30609 Use after free in Sign-In | ||
| CVE-2021-30608 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30608 Use after free in Web Share | ||
| CVE-2021-30607 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30607 Use after free in Permissions | ||
| CVE-2021-30606 | Hig | 0.58 | 8.8 | 0.04 | Sep 3, 2021 | Chromium: CVE-2021-30606 Use after free in Blink | ||
| CVE-2021-37705 | Cri | 0.58 | 10.0 | 0.02 | Aug 13, 2021 | OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable OneFuzz instance. To… | ||
| CVE-2021-36947 | Hig | 0.58 | 8.8 | 0.07 | Aug 12, 2021 | Windows Print Spooler Remote Code Execution Vulnerability | ||
| CVE-2021-36936 | Hig | 0.58 | 8.8 | 0.07 | Aug 12, 2021 | Windows Print Spooler Remote Code Execution Vulnerability | ||
| CVE-2021-27076 | Hig | 0.58 | 8.8 | 0.16 | Mar 11, 2021 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2021-24066 | Hig | 0.58 | 8.8 | 0.06 | Feb 25, 2021 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2021-21157 | Hig | 0.58 | 8.8 | 0.09 | Feb 22, 2021 | Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2021-21128 | Hig | 0.58 | 8.8 | 0.07 | Feb 9, 2021 | Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2021-21127 | Hig | 0.58 | 8.8 | 0.06 | Feb 9, 2021 | Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension. | ||
| CVE-2021-21122 | Hig | 0.58 | 8.8 | 0.07 | Feb 9, 2021 | Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2021-21120 | Hig | 0.58 | 8.8 | 0.07 | Feb 9, 2021 | Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2021-21119 | Hig | 0.58 | 8.8 | 0.07 | Feb 9, 2021 | Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2021-1678 | Hig | 0.58 | 8.8 | 0.09 | Jan 12, 2021 | Windows Print Spooler Spoofing Vulnerability | ||
| CVE-2021-1636 | Hig | 0.58 | 8.8 | 0.06 | Jan 12, 2021 | Microsoft SQL Elevation of Privilege Vulnerability | ||
| CVE-2020-17061 | Hig | 0.58 | 8.8 | 0.04 | Nov 11, 2020 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2020-17042 | Hig | 0.58 | 8.8 | 0.05 | Nov 11, 2020 | Windows Print Spooler Remote Code Execution Vulnerability | ||
| CVE-2020-16911 | Hig | 0.58 | 8.8 | 0.04 | Oct 16, 2020 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install… | ||
| CVE-2020-16898 | Hig | 0.58 | 8.8 | 0.11 | Oct 16, 2020 | A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client. To… | ||
| CVE-2020-1523 | Hig | 0.58 | 8.9 | 0.02 | Sep 11, 2020 | A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data. To exploit the vulnerability, an attacker would need to be… | ||
| CVE-2020-1129 | Hig | 0.58 | 8.8 | 0.04 | Sep 11, 2020 | A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change,… | ||
| CVE-2020-0922 | Hig | 0.58 | 8.8 | 0.05 | Sep 11, 2020 | A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have… | ||
| CVE-2020-1585 | Hig | 0.58 | 8.8 | 0.05 | Aug 17, 2020 | A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or… | ||
| CVE-2020-1583 | Hig | 0.58 | 8.8 | 0.05 | Aug 17, 2020 | An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could… | ||
| CVE-2020-1561 | Hig | 0.58 | 8.8 | 0.04 | Aug 17, 2020 | A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open… | ||
| CVE-2020-1555 | Hig | 0.58 | 8.8 | 0.05 | Aug 17, 2020 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An… | ||
| CVE-2020-1504 | Hig | 0.58 | 8.8 | 0.04 | Aug 17, 2020 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is… | ||
| CVE-2020-1498 | Hig | 0.58 | 8.8 | 0.04 | Aug 17, 2020 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is… | ||
| CVE-2020-1496 | Hig | 0.58 | 8.8 | 0.04 | Aug 17, 2020 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is… | ||
| CVE-2020-1495 | Hig | 0.58 | 8.8 | 0.04 | Aug 17, 2020 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is… | ||
| CVE-2020-1494 | Hig | 0.58 | 8.8 | 0.04 | Aug 17, 2020 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is… | ||
| CVE-2020-1472 | Med | 0.58 | 5.5 | 1.00 | KEV | Aug 17, 2020 | An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially… | |
| CVE-2020-1448 | Hig | 0.58 | 8.8 | 0.10 | Jul 14, 2020 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447. |
- risk 0.58cvss 8.1epss 0.70
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.05
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.58cvss 7.0epss 0.03
Windows User Profile Service Elevation of Privilege Vulnerability
- risk 0.58cvss 8.8epss 0.14
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.58cvss 7.0epss 0.03
Open Management Infrastructure Elevation of Privilege Vulnerability
- risk 0.58cvss 8.8epss 0.05
Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30624 Use after free in Autofill
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30623 Use after free in Bookmarks
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30622 Use after free in WebApp Installs
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30616 Use after free in Media
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30613 Use after free in Base internals
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30610 Use after free in Extensions API
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30609 Use after free in Sign-In
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30608 Use after free in Web Share
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30607 Use after free in Permissions
- risk 0.58cvss 8.8epss 0.04
Chromium: CVE-2021-30606 Use after free in Blink
- risk 0.58cvss 10.0epss 0.02
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable OneFuzz instance. To…
- risk 0.58cvss 8.8epss 0.07
Windows Print Spooler Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.07
Windows Print Spooler Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.16
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.06
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.09
Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.58cvss 8.8epss 0.07
Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.58cvss 8.8epss 0.06
Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension.
- risk 0.58cvss 8.8epss 0.07
Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.58cvss 8.8epss 0.07
Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.58cvss 8.8epss 0.07
Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
- risk 0.58cvss 8.8epss 0.09
Windows Print Spooler Spoofing Vulnerability
- risk 0.58cvss 8.8epss 0.06
Microsoft SQL Elevation of Privilege Vulnerability
- risk 0.58cvss 8.8epss 0.04
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.05
Windows Print Spooler Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.04
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install…
- risk 0.58cvss 8.8epss 0.11
A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client. To…
- risk 0.58cvss 8.9epss 0.02
A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data. To exploit the vulnerability, an attacker would need to be…
- risk 0.58cvss 8.8epss 0.04
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change,…
- risk 0.58cvss 8.8epss 0.05
A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have…
- risk 0.58cvss 8.8epss 0.05
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or…
- risk 0.58cvss 8.8epss 0.05
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could…
- risk 0.58cvss 8.8epss 0.04
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open…
- risk 0.58cvss 8.8epss 0.05
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An…
- risk 0.58cvss 8.8epss 0.04
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is…
- risk 0.58cvss 8.8epss 0.04
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is…
- risk 0.58cvss 8.8epss 0.04
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is…
- risk 0.58cvss 8.8epss 0.04
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is…
- risk 0.58cvss 8.8epss 0.04
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is…
- risk 0.58cvss 5.5epss 1.00
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially…
- risk 0.58cvss 8.8epss 0.10
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.
Page 21 of 314