VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2022-21921MedJan 11, 2022
    risk 0.29cvss 4.4epss 0.01

    Windows Defender Credential Guard Security Feature Bypass Vulnerability

  • CVE-2022-21894MedJan 11, 2022
    risk 0.29cvss 4.4epss 0.07

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2021-41375MedNov 10, 2021
    risk 0.29cvss 4.4epss 0.01

    Azure Sphere Information Disclosure Vulnerability

  • CVE-2021-41371MedNov 10, 2021
    risk 0.29cvss 4.4epss 0.02

    Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

  • CVE-2021-38631MedNov 10, 2021
    risk 0.29cvss 4.4epss 0.02

    Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

  • CVE-2021-36956MedSep 15, 2021
    risk 0.29cvss 4.4epss 0.01

    Azure Sphere Information Disclosure Vulnerability

  • CVE-2021-36931MedAug 26, 2021
    risk 0.29cvss 4.4epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2021-34532MedAug 12, 2021
    risk 0.29cvss 5.5epss 0.01

    ASP.NET Core and Visual Studio Information Disclosure Vulnerability

  • CVE-2021-26428MedAug 12, 2021
    risk 0.29cvss 4.4epss 0.01

    Azure Sphere Information Disclosure Vulnerability

  • CVE-2021-28447MedApr 13, 2021
    risk 0.29cvss 4.4epss 0.02

    Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability

  • CVE-2021-27094MedApr 13, 2021
    risk 0.29cvss 4.4epss 0.01

    Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability

  • CVE-2020-1592MedSep 11, 2020
    risk 0.29cvss 4.4epss 0.01

    An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory. To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this…

  • CVE-2020-1589MedSep 11, 2020
    risk 0.29cvss 4.4epss 0.01

    An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an…

  • CVE-2020-1444MedJul 14, 2020
    risk 0.29cvss 4.3epss 0.09

    A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.

  • CVE-2020-0621MedJan 14, 2020
    risk 0.29cvss 4.4epss 0.01

    A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password update, aka 'Windows Security Feature Bypass Vulnerability'.

  • CVE-2019-1481MedDec 10, 2019
    risk 0.29cvss 4.3epss 0.12

    An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memory, aka 'Windows Media Player Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1480.

  • CVE-2019-1202MedAug 14, 2019
    risk 0.29cvss 4.4epss 0.02

    An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To exploit this vulnerability, the attacker could run a…

  • CVE-2019-0941MedJun 12, 2019
    risk 0.29cvss 4.4epss 0.03

    A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests. An attacker who successfully exploited this vulnerability could perform a temporary denial of service against pages configured to use request filtering. To…

  • CVE-2019-0976MedMay 16, 2019
    risk 0.29cvss 5.5epss 0.01

    A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify contents of the intermediate build folder (by default "obj"), aka 'NuGet Package Manager Tampering Vulnerability'.

  • CVE-2019-0839MedApr 9, 2019
    risk 0.29cvss 4.4epss 0.03

    An information disclosure vulnerability exists when the Terminal Services component improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0838.

  • CVE-2018-8324MedJul 11, 2018
    risk 0.29cvss 4.3epss 0.10

    An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8289, CVE-2018-8297, CVE-2018-8325.

  • CVE-2018-8297MedJul 11, 2018
    risk 0.29cvss 4.3epss 0.10

    An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8289, CVE-2018-8324, CVE-2018-8325.

  • CVE-2018-8289MedJul 11, 2018
    risk 0.29cvss 4.3epss 0.10

    An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8297, CVE-2018-8324, CVE-2018-8325.

  • CVE-2018-8201MedJun 14, 2018
    risk 0.29cvss 4.5epss 0.02

    A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10,…

  • CVE-2018-8151MedMay 9, 2018
    risk 0.29cvss 4.3epss 0.09

    An information disclosure vulnerability exists when Microsoft Exchange improperly handles objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8154.

  • CVE-2018-0766MedJan 4, 2018
    risk 0.29cvss 4.3epss 0.09

    Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the Microsoft Edge PDF Reader handles objects in memory, aka "Microsoft Edge Information…

  • CVE-2017-11848MedNov 15, 2017
    risk 0.29cvss 4.3epss 0.08

    Internet Explorer in Microsoft Microsoft Windows 7 SP1, Windows Server 2008 SP2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to detect the navigation…

  • CVE-2017-8726MedOct 13, 2017
    risk 0.29cvss 4.3epss 0.07

    Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how affected Microsoft scripting engines handle objects in memory, aka "Microsoft Edge Memory Corruption…

  • CVE-2017-11818MedOct 13, 2017
    risk 0.29cvss 4.5epss 0.02

    The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass vulnerability when it fails to validate an integrity-level check, aka…

  • CVE-2017-8736MedSep 13, 2017
    risk 0.29cvss 4.3epss 0.09

    Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to obtain specific…

  • CVE-2017-8555MedJun 15, 2017
    risk 0.29cvss 4.3epss 0.16

    Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass…

  • CVE-2017-0164MedApr 12, 2017
    risk 0.29cvss 4.4epss 0.04

    A denial of service vulnerability exists in Windows 10 1607 and Windows Server 2016 Active Directory when an authenticated attacker sends malicious search queries, aka "Active Directory Denial of Service Vulnerability."

  • CVE-2017-0154MedMar 17, 2017
    risk 0.29cvss 4.4epss 0.09

    Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of…

  • CVE-2017-0069MedMar 17, 2017
    risk 0.29cvss 4.3epss 0.11

    Microsoft Edge allows remote attackers to spoof web content via a crafted web site, aka "Microsoft Edge Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0012 and CVE-2017-0033.

  • CVE-2017-0068MedMar 17, 2017
    risk 0.29cvss 4.3epss 0.17

    Browsers in Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011,…

  • CVE-2017-0057MedMar 17, 2017
    risk 0.29cvss 4.3epss 0.15

    DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensitive information via (1) convincing a workstation user to…

  • CVE-2017-0033MedMar 17, 2017
    risk 0.29cvss 4.3epss 0.09

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a crafted web site, aka "Microsoft Browser Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0012 and CVE-2017-0069.

  • CVE-2017-0012MedMar 17, 2017
    risk 0.29cvss 4.3epss 0.10

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a crafted web site, aka "Microsoft Browser Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0033 and CVE-2017-0069.

  • CVE-2016-7284MedDec 20, 2016
    risk 0.29cvss 4.3epss 0.16

    Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

  • CVE-2016-0138MedSep 14, 2016
    risk 0.29cvss 4.3epss 0.16

    Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Outlook application…

  • CVE-2016-3287MedJul 13, 2016
    risk 0.29cvss 4.4epss 0.02

    Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection mechanism by leveraging administrative access to install a crafted policy, aka "Secure Boot Security Feature Bypass."

  • CVE-2016-3244MedJul 13, 2016
    risk 0.29cvss 4.3epss 0.20

    Microsoft Edge allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Edge Security Feature Bypass."

  • CVE-2016-0080MedFeb 10, 2016
    risk 0.29cvss 4.3epss 0.16

    Microsoft Edge mishandles exceptions during window-message dispatch operations, which allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Edge ASLR Bypass."

  • CVE-2016-0077MedFeb 10, 2016
    risk 0.29cvss 4.3epss 0.12

    Microsoft Internet Explorer 9 through 11 and Microsoft Edge misparse HTTP responses, which allows remote attackers to spoof web sites via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."

  • CVE-2016-0012MedJan 13, 2016
    risk 0.29cvss 4.3epss 0.12

    Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT…

  • CVE-2016-0008MedJan 13, 2016
    risk 0.29cvss 4.3epss 0.15

    The graphics device interface in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to bypass the ASLR protection mechanism via unspecified…

  • CVE-2010-3243MedOct 13, 2010
    risk 0.29cvss 4.3epss 0.16

    Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or…

  • CVE-1999-0524MedAug 1, 1997
    risk 0.29cvss 4.0epss 0.32

    ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.

  • CVE-2026-66798MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.01

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62882MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.01

    Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.

Page 213 of 314