VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2022-23270HigMay 10, 2022
    risk 0.58cvss 8.1epss 0.70

    Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

  • CVE-2022-21984HigFeb 9, 2022
    risk 0.58cvss 8.8epss 0.05

    Windows DNS Server Remote Code Execution Vulnerability

  • CVE-2022-21919HigKEVJan 11, 2022
    risk 0.58cvss 7.0epss 0.03

    Windows User Profile Service Elevation of Privilege Vulnerability

  • CVE-2021-38666HigNov 10, 2021
    risk 0.58cvss 8.8epss 0.14

    Remote Desktop Client Remote Code Execution Vulnerability

  • CVE-2021-38649HigKEVSep 15, 2021
    risk 0.58cvss 7.0epss 0.03

    Open Management Infrastructure Elevation of Privilege Vulnerability

  • CVE-2021-36965HigSep 15, 2021
    risk 0.58cvss 8.8epss 0.05

    Windows WLAN AutoConfig Service Remote Code Execution Vulnerability

  • CVE-2021-30624HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30624 Use after free in Autofill

  • CVE-2021-30623HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30623 Use after free in Bookmarks

  • CVE-2021-30622HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30622 Use after free in WebApp Installs

  • CVE-2021-30620HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink

  • CVE-2021-30618HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30618 Inappropriate implementation in DevTools

  • CVE-2021-30616HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30616 Use after free in Media

  • CVE-2021-30614HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip

  • CVE-2021-30613HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30613 Use after free in Base internals

  • CVE-2021-30610HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30610 Use after free in Extensions API

  • CVE-2021-30609HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30609 Use after free in Sign-In

  • CVE-2021-30608HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30608 Use after free in Web Share

  • CVE-2021-30607HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30607 Use after free in Permissions

  • CVE-2021-30606HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30606 Use after free in Blink

  • CVE-2021-37705CriAug 13, 2021
    risk 0.58cvss 10.0epss 0.02

    OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable OneFuzz instance. To…

  • CVE-2021-36947HigAug 12, 2021
    risk 0.58cvss 8.8epss 0.07

    Windows Print Spooler Remote Code Execution Vulnerability

  • CVE-2021-36936HigAug 12, 2021
    risk 0.58cvss 8.8epss 0.07

    Windows Print Spooler Remote Code Execution Vulnerability

  • CVE-2021-27076HigMar 11, 2021
    risk 0.58cvss 8.8epss 0.16

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2021-24066HigFeb 25, 2021
    risk 0.58cvss 8.8epss 0.06

    Microsoft SharePoint Remote Code Execution Vulnerability

  • CVE-2021-21157HigFeb 22, 2021
    risk 0.58cvss 8.8epss 0.09

    Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21128HigFeb 9, 2021
    risk 0.58cvss 8.8epss 0.07

    Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21127HigFeb 9, 2021
    risk 0.58cvss 8.8epss 0.06

    Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension.

  • CVE-2021-21122HigFeb 9, 2021
    risk 0.58cvss 8.8epss 0.07

    Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21120HigFeb 9, 2021
    risk 0.58cvss 8.8epss 0.07

    Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21119HigFeb 9, 2021
    risk 0.58cvss 8.8epss 0.07

    Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-1678HigJan 12, 2021
    risk 0.58cvss 8.8epss 0.09

    Windows Print Spooler Spoofing Vulnerability

  • CVE-2021-1636HigJan 12, 2021
    risk 0.58cvss 8.8epss 0.06

    Microsoft SQL Elevation of Privilege Vulnerability

  • CVE-2020-17061HigNov 11, 2020
    risk 0.58cvss 8.8epss 0.04

    Microsoft SharePoint Remote Code Execution Vulnerability

  • CVE-2020-17042HigNov 11, 2020
    risk 0.58cvss 8.8epss 0.05

    Windows Print Spooler Remote Code Execution Vulnerability

  • CVE-2020-16911HigOct 16, 2020
    risk 0.58cvss 8.8epss 0.04

    A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install…

  • CVE-2020-16898HigOct 16, 2020
    risk 0.58cvss 8.8epss 0.11

    A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client. To…

  • CVE-2020-1523HigSep 11, 2020
    risk 0.58cvss 8.9epss 0.02

    A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data. To exploit the vulnerability, an attacker would need to be…

  • CVE-2020-1129HigSep 11, 2020
    risk 0.58cvss 8.8epss 0.04

    A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change,…

  • CVE-2020-0922HigSep 11, 2020
    risk 0.58cvss 8.8epss 0.05

    A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have…

  • CVE-2020-1585HigAug 17, 2020
    risk 0.58cvss 8.8epss 0.05

    A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or…

  • CVE-2020-1583HigAug 17, 2020
    risk 0.58cvss 8.8epss 0.05

    An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could…

  • CVE-2020-1561HigAug 17, 2020
    risk 0.58cvss 8.8epss 0.04

    A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open…

  • CVE-2020-1555HigAug 17, 2020
    risk 0.58cvss 8.8epss 0.05

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An…

  • CVE-2020-1504HigAug 17, 2020
    risk 0.58cvss 8.8epss 0.04

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is…

  • CVE-2020-1498HigAug 17, 2020
    risk 0.58cvss 8.8epss 0.04

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is…

  • CVE-2020-1496HigAug 17, 2020
    risk 0.58cvss 8.8epss 0.04

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is…

  • CVE-2020-1495HigAug 17, 2020
    risk 0.58cvss 8.8epss 0.04

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is…

  • CVE-2020-1494HigAug 17, 2020
    risk 0.58cvss 8.8epss 0.04

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is…

  • CVE-2020-1472MedKEVAug 17, 2020
    risk 0.58cvss 5.5epss 1.00

    An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially…

  • CVE-2020-1448HigJul 14, 2020
    risk 0.58cvss 8.8epss 0.10

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.

Page 21 of 314