Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-29334 | Med | 0.28 | 4.3 | 0.01 | Apr 28, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2023-28284 | Med | 0.28 | 4.3 | 0.01 | Apr 11, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2023-21729 | Med | 0.28 | 4.3 | 0.01 | Apr 11, 2023 | Remote Procedure Call Runtime Information Disclosure Vulnerability | ||
| CVE-2023-24911 | Med | 0.28 | 4.3 | 0.01 | Mar 14, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2023-21794 | Med | 0.28 | 4.3 | 0.01 | Feb 14, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2022-23551 | Med | 0.28 | 5.3 | 0.01 | Dec 21, 2022 | aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request made with… | ||
| CVE-2022-44688 | Med | 0.28 | 4.3 | 0.01 | Dec 13, 2022 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2022-45306 | Med | 0.28 | 4.3 | 0.00 | Nov 29, 2022 | Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder. | ||
| CVE-2022-38030 | Med | 0.28 | 4.3 | 0.01 | Oct 11, 2022 | Windows USB Serial Driver Information Disclosure Vulnerability | ||
| CVE-2022-37981 | Med | 0.28 | 4.3 | 0.02 | Oct 11, 2022 | Windows Event Logging Service Denial of Service Vulnerability | ||
| CVE-2022-26905 | Med | 0.28 | 4.3 | 0.02 | Jun 1, 2022 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2022-26907 | Med | 0.28 | 5.3 | 0.02 | Apr 15, 2022 | Azure SDK for .NET Information Disclosure Vulnerability | ||
| CVE-2022-24523 | Med | 0.28 | 4.3 | 0.01 | Apr 5, 2022 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2022-21968 | Med | 0.28 | 4.3 | 0.02 | Feb 9, 2022 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | ||
| CVE-2022-23258 | Med | 0.28 | 4.3 | 0.02 | Jan 25, 2022 | Microsoft Edge for Android Spoofing Vulnerability | ||
| CVE-2021-43908 | Med | 0.28 | 4.3 | 0.03 | Dec 15, 2021 | Visual Studio Code Spoofing Vulnerability | ||
| CVE-2021-41351 | Med | 0.28 | 4.3 | 0.04 | Nov 10, 2021 | Microsoft Edge (Chrome based) Spoofing on IE Mode | ||
| CVE-2021-27066 | Med | 0.28 | 4.3 | 0.03 | Mar 11, 2021 | Windows Admin Center Security Feature Bypass Vulnerability | ||
| CVE-2021-24082 | Med | 0.28 | 4.3 | 0.02 | Feb 25, 2021 | Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability | ||
| CVE-2021-3339 | Med | 0.28 | 4.3 | 0.02 | Feb 19, 2021 | ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen. | ||
| CVE-2020-17153 | Med | 0.28 | 4.3 | 0.02 | Dec 10, 2020 | Microsoft Edge for Android Spoofing Vulnerability | ||
| CVE-2020-17015 | Med | 0.28 | 4.3 | 0.02 | Nov 11, 2020 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2020-8927 | Med | 0.28 | 5.3 | 0.03 | Sep 15, 2020 | A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to… | ||
| CVE-2020-1044 | Med | 0.28 | 4.3 | 0.02 | Sep 11, 2020 | A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallowed by an… | ||
| CVE-2020-1567 | Med | 0.28 | 4.2 | 0.04 | Aug 17, 2020 | A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully… | ||
| CVE-2020-1462 | Med | 0.28 | 4.3 | 0.04 | Jul 14, 2020 | An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'. | ||
| CVE-2020-1432 | Med | 0.28 | 4.3 | 0.04 | Jul 14, 2020 | An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'. | ||
| CVE-2020-1259 | Med | 0.28 | 4.3 | 0.03 | Jun 9, 2020 | A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Guardian Service Security Feature Bypass Vulnerability'. | ||
| CVE-2020-1229 | Med | 0.28 | 4.3 | 0.04 | Jun 9, 2020 | A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'. | ||
| CVE-2020-1096 | Med | 0.28 | 4.2 | 0.02 | May 21, 2020 | A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who… | ||
| CVE-2020-1059 | Med | 0.28 | 4.3 | 0.02 | May 21, 2020 | A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could either spoof content… | ||
| CVE-2019-19677 | Med | 0.28 | 4.3 | 0.01 | Mar 18, 2020 | arxes-tolina 3.0.0 allows User Enumeration. | ||
| CVE-2020-0885 | Med | 0.28 | 4.3 | 0.05 | Mar 12, 2020 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows Graphics Component Information Disclosure Vulnerability'. | ||
| CVE-2020-0706 | Med | 0.28 | 4.3 | 0.05 | Feb 11, 2020 | An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests, aka 'Microsoft Browser Information Disclosure Vulnerability'. | ||
| CVE-2019-1480 | Med | 0.28 | 4.3 | 0.05 | Dec 10, 2019 | An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memory, aka 'Windows Media Player Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1481. | ||
| CVE-2019-19616 | Med | 0.28 | 4.3 | 0.01 | Dec 6, 2019 | An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV before 2017 allows an attacker to download arbitrary files by specifying arbitrary values for the recId and filename parameters of the… | ||
| CVE-2019-1413 | Med | 0.28 | 4.3 | 0.01 | Nov 12, 2019 | A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'. | ||
| CVE-2019-1357 | Med | 0.28 | 4.3 | 0.02 | Oct 10, 2019 | A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608. | ||
| CVE-2019-0608 | Med | 0.28 | 4.3 | 0.02 | Oct 10, 2019 | A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357. | ||
| CVE-2019-1220 | Med | 0.28 | 4.3 | 0.04 | Sep 11, 2019 | A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'. | ||
| CVE-2019-1204 | Med | 0.28 | 4.3 | 0.05 | Aug 14, 2019 | An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a… | ||
| CVE-2019-1192 | Med | 0.28 | 4.3 | 0.04 | Aug 14, 2019 | A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An… | ||
| CVE-2019-1172 | Med | 0.28 | 4.3 | 0.04 | Aug 14, 2019 | An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an attacker would… | ||
| CVE-2019-1030 | Med | 0.28 | 4.3 | 0.06 | Aug 14, 2019 | An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability,… | ||
| CVE-2019-0920 | Med | 0.28 | 4.3 | 0.05 | Jun 12, 2019 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who… | ||
| CVE-2019-0762 | Med | 0.28 | 4.3 | 0.05 | Apr 9, 2019 | A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'. | ||
| CVE-2019-0654 | Med | 0.28 | 4.3 | 0.04 | Mar 5, 2019 | A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'. | ||
| CVE-2019-0643 | Med | 0.28 | 4.3 | 0.06 | Mar 5, 2019 | An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'. | ||
| CVE-2018-8604 | Med | 0.28 | 4.3 | 0.03 | Dec 12, 2018 | A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server. | ||
| CVE-2018-8580 | Med | 0.28 | 4.3 | 0.04 | Dec 12, 2018 | An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability."… |
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.01
Remote Procedure Call Runtime Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 5.3epss 0.01
aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request made with…
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.00
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.
- risk 0.28cvss 4.3epss 0.01
Windows USB Serial Driver Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.02
Windows Event Logging Service Denial of Service Vulnerability
- risk 0.28cvss 4.3epss 0.02
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 5.3epss 0.02
Azure SDK for .NET Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.02
Microsoft SharePoint Server Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
Microsoft Edge for Android Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.03
Visual Studio Code Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.04
Microsoft Edge (Chrome based) Spoofing on IE Mode
- risk 0.28cvss 4.3epss 0.03
Windows Admin Center Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.
- risk 0.28cvss 4.3epss 0.02
Microsoft Edge for Android Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.28cvss 5.3epss 0.03
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to…
- risk 0.28cvss 4.3epss 0.02
A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallowed by an…
- risk 0.28cvss 4.2epss 0.04
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully…
- risk 0.28cvss 4.3epss 0.04
An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'.
- risk 0.28cvss 4.3epss 0.04
An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'.
- risk 0.28cvss 4.3epss 0.03
A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Guardian Service Security Feature Bypass Vulnerability'.
- risk 0.28cvss 4.3epss 0.04
A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
- risk 0.28cvss 4.2epss 0.02
A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who…
- risk 0.28cvss 4.3epss 0.02
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could either spoof content…
- risk 0.28cvss 4.3epss 0.01
arxes-tolina 3.0.0 allows User Enumeration.
- risk 0.28cvss 4.3epss 0.05
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows Graphics Component Information Disclosure Vulnerability'.
- risk 0.28cvss 4.3epss 0.05
An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests, aka 'Microsoft Browser Information Disclosure Vulnerability'.
- risk 0.28cvss 4.3epss 0.05
An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memory, aka 'Windows Media Player Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1481.
- risk 0.28cvss 4.3epss 0.01
An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV before 2017 allows an attacker to download arbitrary files by specifying arbitrary values for the recId and filename parameters of the…
- risk 0.28cvss 4.3epss 0.01
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.
- risk 0.28cvss 4.3epss 0.02
A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608.
- risk 0.28cvss 4.3epss 0.02
A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357.
- risk 0.28cvss 4.3epss 0.04
A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'.
- risk 0.28cvss 4.3epss 0.05
An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a…
- risk 0.28cvss 4.3epss 0.04
A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An…
- risk 0.28cvss 4.3epss 0.04
An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an attacker would…
- risk 0.28cvss 4.3epss 0.06
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability,…
- risk 0.28cvss 4.3epss 0.05
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who…
- risk 0.28cvss 4.3epss 0.05
A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'.
- risk 0.28cvss 4.3epss 0.04
A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'.
- risk 0.28cvss 4.3epss 0.06
An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'.
- risk 0.28cvss 4.3epss 0.03
A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server.
- risk 0.28cvss 4.3epss 0.04
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability."…
Page 215 of 314