VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2021-26439MedSep 2, 2021
    risk 0.30cvss 4.6epss 0.03

    Microsoft Edge for Android Information Disclosure Vulnerability

  • CVE-2021-26418MedMay 11, 2021
    risk 0.30cvss 4.6epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-24104MedMar 11, 2021
    risk 0.30cvss 4.6epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-1717MedJan 12, 2021
    risk 0.30cvss 4.6epss 0.02

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-1641MedJan 12, 2021
    risk 0.30cvss 4.6epss 0.02

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2020-1205MedSep 11, 2020
    risk 0.30cvss 4.6epss 0.02

    A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected…

  • CVE-2020-0943MedApr 15, 2020
    risk 0.30cvss 4.6epss 0.01

    An authentication bypass vulnerability exists in Microsoft YourPhoneCompanion application for Android, in the way the application processes notifications generated by work profiles.This could allow an unauthenticated attacker to view notifications, aka 'Microsoft YourPhone…

  • CVE-2019-1460MedJan 24, 2020
    risk 0.30cvss 4.6epss 0.01

    A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing Vulnerability'.

  • CVE-2019-1368MedOct 10, 2019
    risk 0.30cvss 4.6epss 0.01

    A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'.

  • CVE-2019-1294MedSep 11, 2019
    risk 0.30cvss 4.6epss 0.01

    A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'.

  • CVE-2019-0622MedJan 8, 2019
    risk 0.30cvss 4.6epss 0.02

    An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vulnerability." This affects Skype 8.35.

  • CVE-2018-8566MedNov 14, 2018
    risk 0.30cvss 4.6epss 0.01

    A security feature bypass vulnerability exists when Windows improperly suspends BitLocker Device Encryption, aka "BitLocker Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.

  • CVE-2018-8253MedAug 15, 2018
    risk 0.30cvss 4.6epss 0.02

    An elevation of privilege vulnerability exists when Microsoft Cortana allows arbitrary website browsing on the lockscreen, aka "Microsoft Cortana Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10.

  • CVE-2017-0140MedMar 17, 2017
    risk 0.30cvss 4.2epss 0.28

    Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135.

  • CVE-2017-0066MedMar 17, 2017
    risk 0.30cvss 4.2epss 0.29

    Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0135 and CVE-2017-0140.

  • CVE-2017-0065MedMar 17, 2017
    risk 0.30cvss 4.3epss 0.27

    Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017,…

  • CVE-2016-0059MedFeb 10, 2016
    risk 0.30cvss 4.3epss 0.24

    The Hyperlink Object Library in Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted URL in a (1) e-mail message or (2) Office document, aka "Internet Explorer Information Disclosure Vulnerability."

  • CVE-2016-0005MedJan 13, 2016
    risk 0.30cvss 4.3epss 0.36

    Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability."

  • CVE-2007-5460MedOct 15, 2007
    risk 0.30cvss 4.6epss 0.02

    Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the device, which might make it easier for attackers to decode a PIN/Password obtained…

  • CVE-2026-58616MedAug 28, 2026
    risk 0.29cvss 4.4epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.

  • CVE-2026-49336MedJun 19, 2026
    risk 0.29cvss epss 0.01

    @microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-preview.101, `@microsoft/kiota-http-fetchlibrary`'s `RedirectHandler` is documented as stripping `Authorization` and `Cookie` from…

  • CVE-2026-46383MedMay 15, 2026
    risk 0.29cvss 5.5epss 0.01

    Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install on supported Python 3.10 and 3.11 runtimes.…

  • CVE-2026-41100MedMay 12, 2026
    risk 0.29cvss 4.4epss 0.00

    Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.

  • CVE-2026-32209MedMay 12, 2026
    risk 0.29cvss 4.4epss 0.00

    Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-32220MedApr 14, 2026
    risk 0.29cvss 4.4epss 0.00

    Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-27906MedApr 14, 2026
    risk 0.29cvss 4.4epss 0.00

    Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-20962MedJan 13, 2026
    risk 0.29cvss 4.4epss 0.00

    Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.

  • CVE-2026-20825MedJan 13, 2026
    risk 0.29cvss 4.4epss 0.01

    Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.

  • CVE-2025-53765MedAug 12, 2025
    risk 0.29cvss 4.4epss 0.00

    Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.

  • CVE-2025-47969MedJun 10, 2025
    risk 0.29cvss 4.4epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally.

  • CVE-2025-24997MedMar 11, 2025
    risk 0.29cvss 4.4epss 0.01

    Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.

  • CVE-2025-21401MedFeb 15, 2025
    risk 0.29cvss 4.5epss 0.00

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

  • CVE-2025-21267MedFeb 6, 2025
    risk 0.29cvss 4.4epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2024-38123MedAug 13, 2024
    risk 0.29cvss 4.4epss 0.01

    Windows Bluetooth Driver Information Disclosure Vulnerability

  • CVE-2024-35255MedJun 11, 2024
    risk 0.29cvss 5.5epss 0.01

    Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

  • CVE-2024-35253MedJun 11, 2024
    risk 0.29cvss 4.4epss 0.01

    Microsoft Azure File Sync Elevation of Privilege Vulnerability

  • CVE-2024-21305MedJan 9, 2024
    risk 0.29cvss 4.4epss 0.02

    Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability

  • CVE-2023-36722MedOct 10, 2023
    risk 0.29cvss 4.4epss 0.01

    Active Directory Domain Services Information Disclosure Vulnerability

  • CVE-2023-36698MedOct 10, 2023
    risk 0.29cvss 4.4epss 0.00

    Windows Kernel Security Feature Bypass Vulnerability

  • CVE-2023-36736MedSep 12, 2023
    risk 0.29cvss 4.4epss 0.02

    Microsoft Identity Linux Broker Remote Code Execution Vulnerability

  • CVE-2023-38188MedAug 8, 2023
    risk 0.29cvss 4.5epss 0.01

    Azure Apache Hadoop Spoofing Vulnerability

  • CVE-2023-36881MedAug 8, 2023
    risk 0.29cvss 4.5epss 0.01

    Azure Apache Ambari Spoofing Vulnerability

  • CVE-2023-36877MedAug 8, 2023
    risk 0.29cvss 4.5epss 0.01

    Azure Apache Oozie Spoofing Vulnerability

  • CVE-2023-35393MedAug 8, 2023
    risk 0.29cvss 4.5epss 0.01

    Azure Apache Hive Spoofing Vulnerability

  • CVE-2023-28276MedApr 11, 2023
    risk 0.29cvss 4.4epss 0.00

    Windows Group Policy Security Feature Bypass Vulnerability

  • CVE-2022-41066MedNov 9, 2022
    risk 0.29cvss 4.4epss 0.01

    Microsoft Dynamics Business Central Information Disclosure Vulnerability

  • CVE-2022-35821MedAug 9, 2022
    risk 0.29cvss 4.4epss 0.01

    Azure Sphere Information Disclosure Vulnerability

  • CVE-2022-35783MedAug 9, 2022
    risk 0.29cvss 4.4epss 0.02

    Azure Site Recovery Elevation of Privilege Vulnerability

  • CVE-2022-30184MedJun 15, 2022
    risk 0.29cvss 5.5epss 0.05

    .NET and Visual Studio Information Disclosure Vulnerability

  • CVE-2022-22010MedMar 9, 2022
    risk 0.29cvss 4.4epss 0.03

    Media Foundation Information Disclosure Vulnerability

Page 212 of 314