VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2023-29334MedApr 28, 2023
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2023-28284MedApr 11, 2023
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

  • CVE-2023-21729MedApr 11, 2023
    risk 0.28cvss 4.3epss 0.01

    Remote Procedure Call Runtime Information Disclosure Vulnerability

  • CVE-2023-24911MedMar 14, 2023
    risk 0.28cvss 4.3epss 0.01

    Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

  • CVE-2023-21794MedFeb 14, 2023
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2022-23551MedDec 21, 2022
    risk 0.28cvss 5.3epss 0.01

    aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request made with…

  • CVE-2022-44688MedDec 13, 2022
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2022-45306MedNov 29, 2022
    risk 0.28cvss 4.3epss 0.00

    Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.

  • CVE-2022-38030MedOct 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Windows USB Serial Driver Information Disclosure Vulnerability

  • CVE-2022-37981MedOct 11, 2022
    risk 0.28cvss 4.3epss 0.02

    Windows Event Logging Service Denial of Service Vulnerability

  • CVE-2022-26905MedJun 1, 2022
    risk 0.28cvss 4.3epss 0.02

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2022-26907MedApr 15, 2022
    risk 0.28cvss 5.3epss 0.02

    Azure SDK for .NET Information Disclosure Vulnerability

  • CVE-2022-24523MedApr 5, 2022
    risk 0.28cvss 4.3epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2022-21968MedFeb 9, 2022
    risk 0.28cvss 4.3epss 0.02

    Microsoft SharePoint Server Security Feature Bypass Vulnerability

  • CVE-2022-23258MedJan 25, 2022
    risk 0.28cvss 4.3epss 0.02

    Microsoft Edge for Android Spoofing Vulnerability

  • CVE-2021-43908MedDec 15, 2021
    risk 0.28cvss 4.3epss 0.03

    Visual Studio Code Spoofing Vulnerability

  • CVE-2021-41351MedNov 10, 2021
    risk 0.28cvss 4.3epss 0.04

    Microsoft Edge (Chrome based) Spoofing on IE Mode

  • CVE-2021-27066MedMar 11, 2021
    risk 0.28cvss 4.3epss 0.03

    Windows Admin Center Security Feature Bypass Vulnerability

  • CVE-2021-24082MedFeb 25, 2021
    risk 0.28cvss 4.3epss 0.02

    Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability

  • CVE-2021-3339MedFeb 19, 2021
    risk 0.28cvss 4.3epss 0.02

    ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.

  • CVE-2020-17153MedDec 10, 2020
    risk 0.28cvss 4.3epss 0.02

    Microsoft Edge for Android Spoofing Vulnerability

  • CVE-2020-17015MedNov 11, 2020
    risk 0.28cvss 4.3epss 0.02

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2020-8927MedSep 15, 2020
    risk 0.28cvss 5.3epss 0.03

    A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to…

  • CVE-2020-1044MedSep 11, 2020
    risk 0.28cvss 4.3epss 0.02

    A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallowed by an…

  • CVE-2020-1567MedAug 17, 2020
    risk 0.28cvss 4.2epss 0.04

    A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully…

  • CVE-2020-1462MedJul 14, 2020
    risk 0.28cvss 4.3epss 0.04

    An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'.

  • CVE-2020-1432MedJul 14, 2020
    risk 0.28cvss 4.3epss 0.04

    An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'.

  • CVE-2020-1259MedJun 9, 2020
    risk 0.28cvss 4.3epss 0.03

    A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Guardian Service Security Feature Bypass Vulnerability'.

  • CVE-2020-1229MedJun 9, 2020
    risk 0.28cvss 4.3epss 0.04

    A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.

  • CVE-2020-1096MedMay 21, 2020
    risk 0.28cvss 4.2epss 0.02

    A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who…

  • CVE-2020-1059MedMay 21, 2020
    risk 0.28cvss 4.3epss 0.02

    A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could either spoof content…

  • CVE-2019-19677MedMar 18, 2020
    risk 0.28cvss 4.3epss 0.01

    arxes-tolina 3.0.0 allows User Enumeration.

  • CVE-2020-0885MedMar 12, 2020
    risk 0.28cvss 4.3epss 0.05

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows Graphics Component Information Disclosure Vulnerability'.

  • CVE-2020-0706MedFeb 11, 2020
    risk 0.28cvss 4.3epss 0.05

    An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests, aka 'Microsoft Browser Information Disclosure Vulnerability'.

  • CVE-2019-1480MedDec 10, 2019
    risk 0.28cvss 4.3epss 0.05

    An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memory, aka 'Windows Media Player Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1481.

  • CVE-2019-19616MedDec 6, 2019
    risk 0.28cvss 4.3epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV before 2017 allows an attacker to download arbitrary files by specifying arbitrary values for the recId and filename parameters of the…

  • CVE-2019-1413MedNov 12, 2019
    risk 0.28cvss 4.3epss 0.01

    A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.

  • CVE-2019-1357MedOct 10, 2019
    risk 0.28cvss 4.3epss 0.02

    A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608.

  • CVE-2019-0608MedOct 10, 2019
    risk 0.28cvss 4.3epss 0.02

    A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357.

  • CVE-2019-1220MedSep 11, 2019
    risk 0.28cvss 4.3epss 0.04

    A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'.

  • CVE-2019-1204MedAug 14, 2019
    risk 0.28cvss 4.3epss 0.05

    An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a…

  • CVE-2019-1192MedAug 14, 2019
    risk 0.28cvss 4.3epss 0.04

    A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An…

  • CVE-2019-1172MedAug 14, 2019
    risk 0.28cvss 4.3epss 0.04

    An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an attacker would…

  • CVE-2019-1030MedAug 14, 2019
    risk 0.28cvss 4.3epss 0.06

    An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability,…

  • CVE-2019-0920MedJun 12, 2019
    risk 0.28cvss 4.3epss 0.05

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who…

  • CVE-2019-0762MedApr 9, 2019
    risk 0.28cvss 4.3epss 0.05

    A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'.

  • CVE-2019-0654MedMar 5, 2019
    risk 0.28cvss 4.3epss 0.04

    A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'.

  • CVE-2019-0643MedMar 5, 2019
    risk 0.28cvss 4.3epss 0.06

    An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'.

  • CVE-2018-8604MedDec 12, 2018
    risk 0.28cvss 4.3epss 0.03

    A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server.

  • CVE-2018-8580MedDec 12, 2018
    risk 0.28cvss 4.3epss 0.04

    An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability."…

Page 215 of 314