VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2017-0192MedApr 12, 2017
    risk 0.28cvss 4.3epss 0.07

    The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gain sensitive…

  • CVE-2017-0135MedMar 17, 2017
    risk 0.28cvss 4.2epss 0.12

    Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.

  • CVE-2025-59288MedOct 14, 2025
    risk 0.27cvss 5.3epss 0.00

    Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.

  • CVE-2025-21214MedJan 14, 2025
    risk 0.27cvss 4.2epss 0.01

    Windows BitLocker Information Disclosure Vulnerability

  • CVE-2025-21210MedJan 14, 2025
    risk 0.27cvss 4.2epss 0.01

    Windows BitLocker Information Disclosure Vulnerability

  • CVE-2024-38143MedAug 13, 2024
    risk 0.27cvss 4.2epss 0.02

    Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability

  • CVE-2024-0912MedJun 6, 2024
    risk 0.27cvss 4.2epss 0.00

    Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions

  • CVE-2024-28922MedApr 9, 2024
    risk 0.27cvss 4.1epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2024-29049MedApr 4, 2024
    risk 0.27cvss 4.1epss 0.01

    Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability

  • CVE-2024-21304MedFeb 13, 2024
    risk 0.27cvss 4.1epss 0.00

    Trusted Compute Base Elevation of Privilege Vulnerability

  • CVE-2023-36559MedOct 13, 2023
    risk 0.27cvss 4.2epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2022-29127MedMay 10, 2022
    risk 0.27cvss 4.2epss 0.01

    BitLocker Security Feature Bypass Vulnerability

  • CVE-2022-24466MedMay 10, 2022
    risk 0.27cvss 4.1epss 0.01

    Windows Hyper-V Security Feature Bypass Vulnerability

  • CVE-2022-21931MedJan 11, 2022
    risk 0.27cvss 4.2epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2022-21930MedJan 11, 2022
    risk 0.27cvss 4.2epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2021-43221MedNov 24, 2021
    risk 0.27cvss 4.2epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2021-42279MedNov 10, 2021
    risk 0.27cvss 4.2epss 0.02

    Chakra Scripting Engine Memory Corruption Vulnerability

  • CVE-2021-41363MedOct 13, 2021
    risk 0.27cvss 4.2epss 0.00

    Intune Management Extension Security Feature Bypass Vulnerability

  • CVE-2021-31171MedMay 11, 2021
    risk 0.27cvss 4.1epss 0.01

    Microsoft SharePoint Information Disclosure Vulnerability

  • CVE-2021-28316MedApr 13, 2021
    risk 0.27cvss 4.2epss 0.01

    Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability

  • CVE-2021-1705MedJan 12, 2021
    risk 0.27cvss 4.2epss 0.02

    Microsoft Edge (HTML-based) Memory Corruption Vulnerability

  • CVE-2020-16942MedOct 16, 2020
    risk 0.27cvss 4.1epss 0.01

    An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the…

  • CVE-2020-16941MedOct 16, 2020
    risk 0.27cvss 4.1epss 0.01

    An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the…

  • CVE-2020-16884MedSep 11, 2020
    risk 0.27cvss 4.2epss 0.02

    A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of…

  • CVE-2020-1566MedAug 17, 2020
    risk 0.27cvss 4.2epss 0.02

    An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete…

  • CVE-2020-0663MedFeb 11, 2020
    risk 0.27cvss 4.2epss 0.02

    An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a…

  • CVE-2019-1167MedJul 19, 2019
    risk 0.27cvss 4.1epss 0.02

    A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'.

  • CVE-2019-1081MedJun 12, 2019
    risk 0.27cvss 4.2epss 0.02

    An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, in a…

  • CVE-2019-1002MedJun 12, 2019
    risk 0.27cvss 4.2epss 0.02

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…

  • CVE-2018-8435MedSep 13, 2018
    risk 0.27cvss 4.2epss 0.01

    A security feature bypass vulnerability exists when Windows Hyper-V BIOS loader fails to provide a high-entropy source, aka "Windows Hyper-V Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

  • CVE-2016-3325LowSep 14, 2016
    risk 0.27cvss 3.1epss 0.52

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

  • CVE-2025-49728MedSep 16, 2025
    risk 0.26cvss 4.0epss 0.00

    Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2025-29839MedMay 13, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.

  • CVE-2021-4287MedDec 27, 2022
    risk 0.26cvss 5.0epss 0.02

    A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink following. It is…

  • CVE-2021-36943MedAug 12, 2021
    risk 0.26cvss 4.0epss 0.01

    Azure CycleCloud Elevation of Privilege Vulnerability

  • CVE-2020-1033MedSep 11, 2020
    risk 0.26cvss 4.0epss 0.01

    An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. An authenticated attacker could…

  • CVE-2026-45642LowJun 9, 2026
    risk 0.25cvss 3.9epss 0.00

    Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.

  • CVE-2024-26246LowMar 14, 2024
    risk 0.25cvss 3.9epss 0.01

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

  • CVE-2018-8449LowSep 13, 2018
    risk 0.25cvss 3.3epss 0.04

    A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

  • CVE-2018-0966LowApr 12, 2018
    risk 0.25cvss 3.3epss 0.03

    A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

  • CVE-2018-0878LowMar 14, 2018
    risk 0.25cvss 3.1epss 0.21

    Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure…

  • CVE-2025-32016MedApr 9, 2025
    risk 0.24cvss 4.7epss 0.00

    Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This vulnerability affects confidential client applications,…

  • CVE-2023-28301LowApr 11, 2023
    risk 0.24cvss 3.7epss 0.01

    Microsoft Edge (Chromium-based) Tampering Vulnerability

  • CVE-2022-23292LowApr 15, 2022
    risk 0.24cvss 3.7epss 0.01

    Microsoft Power BI Spoofing Vulnerability

  • CVE-2020-0884LowMar 12, 2020
    risk 0.24cvss 3.7epss 0.02

    A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft Visual Studio Spoofing Vulnerability'.

  • CVE-2017-0159LowApr 12, 2017
    risk 0.24cvss 3.7epss 0.05

    A security feature bypass vulnerability exists in Windows 10 1607, Windows Server 2012 R2, and Windows 2016 when ADFS incorrectly treats requests coming from Extranet clients as Intranet requests, aka "ADFS Security Feature Bypass Vulnerability."

  • CVE-2025-49760LowJul 8, 2025
    risk 0.23cvss 3.5epss 0.01

    External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.

  • CVE-2020-24588LowMay 11, 2021
    risk 0.23cvss 3.5epss 0.04

    The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is…

  • CVE-2017-8676LowSep 13, 2017
    risk 0.23cvss 3.3epss 0.04

    The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for…

  • CVE-2017-0042LowMar 17, 2017
    risk 0.23cvss 3.1epss 0.29

    Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 and R2 SP1, Windows Server 2016; Windows Vista SP2; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted…

Page 217 of 314