Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26439 | Med | 0.30 | 4.6 | 0.03 | Sep 2, 2021 | Microsoft Edge for Android Information Disclosure Vulnerability | ||
| CVE-2021-26418 | Med | 0.30 | 4.6 | 0.01 | May 11, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-24104 | Med | 0.30 | 4.6 | 0.01 | Mar 11, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-1717 | Med | 0.30 | 4.6 | 0.02 | Jan 12, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-1641 | Med | 0.30 | 4.6 | 0.02 | Jan 12, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2020-1205 | Med | 0.30 | 4.6 | 0.02 | Sep 11, 2020 | A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected… | ||
| CVE-2020-0943 | Med | 0.30 | 4.6 | 0.01 | Apr 15, 2020 | An authentication bypass vulnerability exists in Microsoft YourPhoneCompanion application for Android, in the way the application processes notifications generated by work profiles.This could allow an unauthenticated attacker to view notifications, aka 'Microsoft YourPhone… | ||
| CVE-2019-1460 | Med | 0.30 | 4.6 | 0.01 | Jan 24, 2020 | A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing Vulnerability'. | ||
| CVE-2019-1368 | Med | 0.30 | 4.6 | 0.01 | Oct 10, 2019 | A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'. | ||
| CVE-2019-1294 | Med | 0.30 | 4.6 | 0.01 | Sep 11, 2019 | A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'. | ||
| CVE-2019-0622 | Med | 0.30 | 4.6 | 0.02 | Jan 8, 2019 | An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vulnerability." This affects Skype 8.35. | ||
| CVE-2018-8566 | Med | 0.30 | 4.6 | 0.01 | Nov 14, 2018 | A security feature bypass vulnerability exists when Windows improperly suspends BitLocker Device Encryption, aka "BitLocker Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. | ||
| CVE-2018-8253 | Med | 0.30 | 4.6 | 0.02 | Aug 15, 2018 | An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscreen, aka "Microsoft Cortana Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10. | ||
| CVE-2017-0140 | Med | 0.30 | 4.2 | 0.28 | Mar 17, 2017 | Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135. | ||
| CVE-2017-0066 | Med | 0.30 | 4.2 | 0.29 | Mar 17, 2017 | Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0135 and CVE-2017-0140. | ||
| CVE-2017-0065 | Med | 0.30 | 4.3 | 0.27 | Mar 17, 2017 | Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017,… | ||
| CVE-2016-0059 | Med | 0.30 | 4.3 | 0.24 | Feb 10, 2016 | The Hyperlink Object Library in Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted URL in a (1) e-mail message or (2) Office document, aka "Internet Explorer Information Disclosure Vulnerability." | ||
| CVE-2016-0005 | Med | 0.30 | 4.3 | 0.36 | Jan 13, 2016 | Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability." | ||
| CVE-2007-5460 | Med | 0.30 | 4.6 | 0.02 | Oct 15, 2007 | Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the device, which might make it easier for attackers to decode a PIN/Password obtained… | ||
| CVE-2026-58616 | Med | 0.29 | 4.4 | 0.00 | Aug 28, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-49336 | Med | 0.29 | — | 0.01 | Jun 19, 2026 | @microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-preview.101, `@microsoft/kiota-http-fetchlibrary`'s `RedirectHandler` is documented as stripping `Authorization` and `Cookie` from… | ||
| CVE-2026-46383 | Med | 0.29 | 5.5 | 0.01 | May 15, 2026 | Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install on supported Python 3.10 and 3.11 runtimes.… | ||
| CVE-2026-41100 | Med | 0.29 | 4.4 | 0.00 | May 12, 2026 | Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. | ||
| CVE-2026-32209 | Med | 0.29 | 4.4 | 0.00 | May 12, 2026 | Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-32220 | Med | 0.29 | 4.4 | 0.00 | Apr 14, 2026 | Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-27906 | Med | 0.29 | 4.4 | 0.00 | Apr 14, 2026 | Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-20962 | Med | 0.29 | 4.4 | 0.00 | Jan 13, 2026 | Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20825 | Med | 0.29 | 4.4 | 0.01 | Jan 13, 2026 | Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. | ||
| CVE-2025-53765 | Med | 0.29 | 4.4 | 0.00 | Aug 12, 2025 | Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally. | ||
| CVE-2025-47969 | Med | 0.29 | 4.4 | 0.01 | Jun 10, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally. | ||
| CVE-2025-24997 | Med | 0.29 | 4.4 | 0.01 | Mar 11, 2025 | Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally. | ||
| CVE-2025-21401 | Med | 0.29 | 4.5 | 0.00 | Feb 15, 2025 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2025-21267 | Med | 0.29 | 4.4 | 0.01 | Feb 6, 2025 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-38123 | Med | 0.29 | 4.4 | 0.01 | Aug 13, 2024 | Windows Bluetooth Driver Information Disclosure Vulnerability | ||
| CVE-2024-35255 | Med | 0.29 | 5.5 | 0.01 | Jun 11, 2024 | Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | ||
| CVE-2024-35253 | Med | 0.29 | 4.4 | 0.01 | Jun 11, 2024 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | ||
| CVE-2024-21305 | Med | 0.29 | 4.4 | 0.02 | Jan 9, 2024 | Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability | ||
| CVE-2023-36722 | Med | 0.29 | 4.4 | 0.01 | Oct 10, 2023 | Active Directory Domain Services Information Disclosure Vulnerability | ||
| CVE-2023-36698 | Med | 0.29 | 4.4 | 0.00 | Oct 10, 2023 | Windows Kernel Security Feature Bypass Vulnerability | ||
| CVE-2023-36736 | Med | 0.29 | 4.4 | 0.02 | Sep 12, 2023 | Microsoft Identity Linux Broker Remote Code Execution Vulnerability | ||
| CVE-2023-38188 | Med | 0.29 | 4.5 | 0.01 | Aug 8, 2023 | Azure Apache Hadoop Spoofing Vulnerability | ||
| CVE-2023-36881 | Med | 0.29 | 4.5 | 0.01 | Aug 8, 2023 | Azure Apache Ambari Spoofing Vulnerability | ||
| CVE-2023-36877 | Med | 0.29 | 4.5 | 0.01 | Aug 8, 2023 | Azure Apache Oozie Spoofing Vulnerability | ||
| CVE-2023-35393 | Med | 0.29 | 4.5 | 0.01 | Aug 8, 2023 | Azure Apache Hive Spoofing Vulnerability | ||
| CVE-2023-28276 | Med | 0.29 | 4.4 | 0.00 | Apr 11, 2023 | Windows Group Policy Security Feature Bypass Vulnerability | ||
| CVE-2022-41066 | Med | 0.29 | 4.4 | 0.01 | Nov 9, 2022 | Microsoft Dynamics Business Central Information Disclosure Vulnerability | ||
| CVE-2022-35821 | Med | 0.29 | 4.4 | 0.01 | Aug 9, 2022 | Azure Sphere Information Disclosure Vulnerability | ||
| CVE-2022-35783 | Med | 0.29 | 4.4 | 0.02 | Aug 9, 2022 | Azure Site Recovery Elevation of Privilege Vulnerability | ||
| CVE-2022-30184 | Med | 0.29 | 5.5 | 0.05 | Jun 15, 2022 | .NET and Visual Studio Information Disclosure Vulnerability | ||
| CVE-2022-22010 | Med | 0.29 | 4.4 | 0.03 | Mar 9, 2022 | Media Foundation Information Disclosure Vulnerability |
- risk 0.30cvss 4.6epss 0.03
Microsoft Edge for Android Information Disclosure Vulnerability
- risk 0.30cvss 4.6epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.30cvss 4.6epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.30cvss 4.6epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.30cvss 4.6epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.30cvss 4.6epss 0.02
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected…
- risk 0.30cvss 4.6epss 0.01
An authentication bypass vulnerability exists in Microsoft YourPhoneCompanion application for Android, in the way the application processes notifications generated by work profiles.This could allow an unauthenticated attacker to view notifications, aka 'Microsoft YourPhone…
- risk 0.30cvss 4.6epss 0.01
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing Vulnerability'.
- risk 0.30cvss 4.6epss 0.01
A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'.
- risk 0.30cvss 4.6epss 0.01
A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'.
- risk 0.30cvss 4.6epss 0.02
An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vulnerability." This affects Skype 8.35.
- risk 0.30cvss 4.6epss 0.01
A security feature bypass vulnerability exists when Windows improperly suspends BitLocker Device Encryption, aka "BitLocker Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
- risk 0.30cvss 4.6epss 0.02
An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscreen, aka "Microsoft Cortana Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10.
- risk 0.30cvss 4.2epss 0.28
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135.
- risk 0.30cvss 4.2epss 0.29
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0135 and CVE-2017-0140.
- risk 0.30cvss 4.3epss 0.27
Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017,…
- risk 0.30cvss 4.3epss 0.24
The Hyperlink Object Library in Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted URL in a (1) e-mail message or (2) Office document, aka "Internet Explorer Information Disclosure Vulnerability."
- risk 0.30cvss 4.3epss 0.36
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability."
- risk 0.30cvss 4.6epss 0.02
Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the device, which might make it easier for attackers to decode a PIN/Password obtained…
- risk 0.29cvss 4.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.
- risk 0.29cvss —epss 0.01
@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-preview.101, `@microsoft/kiota-http-fetchlibrary`'s `RedirectHandler` is documented as stripping `Authorization` and `Cookie` from…
- risk 0.29cvss 5.5epss 0.01
Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install on supported Python 3.10 and 3.11 runtimes.…
- risk 0.29cvss 4.4epss 0.00
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
- risk 0.29cvss 4.4epss 0.00
Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
- risk 0.29cvss 4.4epss 0.00
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
- risk 0.29cvss 4.4epss 0.00
Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.
- risk 0.29cvss 4.4epss 0.00
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.
- risk 0.29cvss 4.4epss 0.01
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.
- risk 0.29cvss 4.4epss 0.00
Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.
- risk 0.29cvss 4.4epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.
- risk 0.29cvss 4.4epss 0.01
Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.
- risk 0.29cvss 4.5epss 0.00
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.29cvss 4.4epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.29cvss 4.4epss 0.01
Windows Bluetooth Driver Information Disclosure Vulnerability
- risk 0.29cvss 5.5epss 0.01
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
- risk 0.29cvss 4.4epss 0.01
Microsoft Azure File Sync Elevation of Privilege Vulnerability
- risk 0.29cvss 4.4epss 0.02
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
- risk 0.29cvss 4.4epss 0.01
Active Directory Domain Services Information Disclosure Vulnerability
- risk 0.29cvss 4.4epss 0.00
Windows Kernel Security Feature Bypass Vulnerability
- risk 0.29cvss 4.4epss 0.02
Microsoft Identity Linux Broker Remote Code Execution Vulnerability
- risk 0.29cvss 4.5epss 0.01
Azure Apache Hadoop Spoofing Vulnerability
- risk 0.29cvss 4.5epss 0.01
Azure Apache Ambari Spoofing Vulnerability
- risk 0.29cvss 4.5epss 0.01
Azure Apache Oozie Spoofing Vulnerability
- risk 0.29cvss 4.5epss 0.01
Azure Apache Hive Spoofing Vulnerability
- risk 0.29cvss 4.4epss 0.00
Windows Group Policy Security Feature Bypass Vulnerability
- risk 0.29cvss 4.4epss 0.01
Microsoft Dynamics Business Central Information Disclosure Vulnerability
- risk 0.29cvss 4.4epss 0.01
Azure Sphere Information Disclosure Vulnerability
- risk 0.29cvss 4.4epss 0.02
Azure Site Recovery Elevation of Privilege Vulnerability
- risk 0.29cvss 5.5epss 0.05
.NET and Visual Studio Information Disclosure Vulnerability
- risk 0.29cvss 4.4epss 0.03
Media Foundation Information Disclosure Vulnerability
Page 212 of 314