Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-0192 | Med | 0.28 | 4.3 | 0.07 | Apr 12, 2017 | The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gain sensitive… | ||
| CVE-2017-0135 | Med | 0.28 | 4.2 | 0.12 | Mar 17, 2017 | Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140. | ||
| CVE-2025-59288 | Med | 0.27 | 5.3 | 0.00 | Oct 14, 2025 | Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network. | ||
| CVE-2025-21214 | Med | 0.27 | 4.2 | 0.01 | Jan 14, 2025 | Windows BitLocker Information Disclosure Vulnerability | ||
| CVE-2025-21210 | Med | 0.27 | 4.2 | 0.01 | Jan 14, 2025 | Windows BitLocker Information Disclosure Vulnerability | ||
| CVE-2024-38143 | Med | 0.27 | 4.2 | 0.02 | Aug 13, 2024 | Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | ||
| CVE-2024-0912 | Med | 0.27 | 4.2 | 0.00 | Jun 6, 2024 | Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions | ||
| CVE-2024-28922 | Med | 0.27 | 4.1 | 0.01 | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2024-29049 | Med | 0.27 | 4.1 | 0.01 | Apr 4, 2024 | Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability | ||
| CVE-2024-21304 | Med | 0.27 | 4.1 | 0.00 | Feb 13, 2024 | Trusted Compute Base Elevation of Privilege Vulnerability | ||
| CVE-2023-36559 | Med | 0.27 | 4.2 | 0.01 | Oct 13, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2022-29127 | Med | 0.27 | 4.2 | 0.01 | May 10, 2022 | BitLocker Security Feature Bypass Vulnerability | ||
| CVE-2022-24466 | Med | 0.27 | 4.1 | 0.01 | May 10, 2022 | Windows Hyper-V Security Feature Bypass Vulnerability | ||
| CVE-2022-21931 | Med | 0.27 | 4.2 | 0.01 | Jan 11, 2022 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2022-21930 | Med | 0.27 | 4.2 | 0.01 | Jan 11, 2022 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2021-43221 | Med | 0.27 | 4.2 | 0.01 | Nov 24, 2021 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2021-42279 | Med | 0.27 | 4.2 | 0.02 | Nov 10, 2021 | Chakra Scripting Engine Memory Corruption Vulnerability | ||
| CVE-2021-41363 | Med | 0.27 | 4.2 | 0.00 | Oct 13, 2021 | Intune Management Extension Security Feature Bypass Vulnerability | ||
| CVE-2021-31171 | Med | 0.27 | 4.1 | 0.01 | May 11, 2021 | Microsoft SharePoint Information Disclosure Vulnerability | ||
| CVE-2021-28316 | Med | 0.27 | 4.2 | 0.01 | Apr 13, 2021 | Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability | ||
| CVE-2021-1705 | Med | 0.27 | 4.2 | 0.02 | Jan 12, 2021 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | ||
| CVE-2020-16942 | Med | 0.27 | 4.1 | 0.01 | Oct 16, 2020 | An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the… | ||
| CVE-2020-16941 | Med | 0.27 | 4.1 | 0.01 | Oct 16, 2020 | An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the… | ||
| CVE-2020-16884 | Med | 0.27 | 4.2 | 0.02 | Sep 11, 2020 | A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of… | ||
| CVE-2020-1566 | Med | 0.27 | 4.2 | 0.02 | Aug 17, 2020 | An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete… | ||
| CVE-2020-0663 | Med | 0.27 | 4.2 | 0.02 | Feb 11, 2020 | An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a… | ||
| CVE-2019-1167 | Med | 0.27 | 4.1 | 0.02 | Jul 19, 2019 | A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'. | ||
| CVE-2019-1081 | Med | 0.27 | 4.2 | 0.02 | Jun 12, 2019 | An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, in a… | ||
| CVE-2019-1002 | Med | 0.27 | 4.2 | 0.02 | Jun 12, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current… | ||
| CVE-2018-8435 | Med | 0.27 | 4.2 | 0.01 | Sep 13, 2018 | A security feature bypass vulnerability exists when Windows Hyper-V BIOS loader fails to provide a high-entropy source, aka "Windows Hyper-V Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | ||
| CVE-2016-3325 | Low | 0.27 | 3.1 | 0.52 | Sep 14, 2016 | Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | ||
| CVE-2025-49728 | Med | 0.26 | 4.0 | 0.00 | Sep 16, 2025 | Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2025-29839 | Med | 0.26 | 4.0 | 0.00 | May 13, 2025 | Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally. | ||
| CVE-2021-4287 | Med | 0.26 | 5.0 | 0.02 | Dec 27, 2022 | A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink following. It is… | ||
| CVE-2021-36943 | Med | 0.26 | 4.0 | 0.01 | Aug 12, 2021 | Azure CycleCloud Elevation of Privilege Vulnerability | ||
| CVE-2020-1033 | Med | 0.26 | 4.0 | 0.01 | Sep 11, 2020 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. An authenticated attacker could… | ||
| CVE-2026-45642 | Low | 0.25 | 3.9 | 0.00 | Jun 9, 2026 | Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack. | ||
| CVE-2024-26246 | Low | 0.25 | 3.9 | 0.01 | Mar 14, 2024 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2018-8449 | Low | 0.25 | 3.3 | 0.04 | Sep 13, 2018 | A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | ||
| CVE-2018-0966 | Low | 0.25 | 3.3 | 0.03 | Apr 12, 2018 | A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | ||
| CVE-2018-0878 | Low | 0.25 | 3.1 | 0.21 | Mar 14, 2018 | Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure… | ||
| CVE-2025-32016 | Med | 0.24 | 4.7 | 0.00 | Apr 9, 2025 | Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This vulnerability affects confidential client applications,… | ||
| CVE-2023-28301 | Low | 0.24 | 3.7 | 0.01 | Apr 11, 2023 | Microsoft Edge (Chromium-based) Tampering Vulnerability | ||
| CVE-2022-23292 | Low | 0.24 | 3.7 | 0.01 | Apr 15, 2022 | Microsoft Power BI Spoofing Vulnerability | ||
| CVE-2020-0884 | Low | 0.24 | 3.7 | 0.02 | Mar 12, 2020 | A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft Visual Studio Spoofing Vulnerability'. | ||
| CVE-2017-0159 | Low | 0.24 | 3.7 | 0.05 | Apr 12, 2017 | A security feature bypass vulnerability exists in Windows 10 1607, Windows Server 2012 R2, and Windows 2016 when ADFS incorrectly treats requests coming from Extranet clients as Intranet requests, aka "ADFS Security Feature Bypass Vulnerability." | ||
| CVE-2025-49760 | Low | 0.23 | 3.5 | 0.01 | Jul 8, 2025 | External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2020-24588 | Low | 0.23 | 3.5 | 0.04 | May 11, 2021 | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is… | ||
| CVE-2017-8676 | Low | 0.23 | 3.3 | 0.04 | Sep 13, 2017 | The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for… | ||
| CVE-2017-0042 | Low | 0.23 | 3.1 | 0.29 | Mar 17, 2017 | Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 and R2 SP1, Windows Server 2016; Windows Vista SP2; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted… |
- risk 0.28cvss 4.3epss 0.07
The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gain sensitive…
- risk 0.28cvss 4.2epss 0.12
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.
- risk 0.27cvss 5.3epss 0.00
Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network.
- risk 0.27cvss 4.2epss 0.01
Windows BitLocker Information Disclosure Vulnerability
- risk 0.27cvss 4.2epss 0.01
Windows BitLocker Information Disclosure Vulnerability
- risk 0.27cvss 4.2epss 0.02
Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
- risk 0.27cvss 4.2epss 0.00
Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions
- risk 0.27cvss 4.1epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.27cvss 4.1epss 0.01
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
- risk 0.27cvss 4.1epss 0.00
Trusted Compute Base Elevation of Privilege Vulnerability
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.27cvss 4.2epss 0.01
BitLocker Security Feature Bypass Vulnerability
- risk 0.27cvss 4.1epss 0.01
Windows Hyper-V Security Feature Bypass Vulnerability
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.27cvss 4.2epss 0.02
Chakra Scripting Engine Memory Corruption Vulnerability
- risk 0.27cvss 4.2epss 0.00
Intune Management Extension Security Feature Bypass Vulnerability
- risk 0.27cvss 4.1epss 0.01
Microsoft SharePoint Information Disclosure Vulnerability
- risk 0.27cvss 4.2epss 0.01
Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability
- risk 0.27cvss 4.2epss 0.02
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
- risk 0.27cvss 4.1epss 0.01
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the…
- risk 0.27cvss 4.1epss 0.01
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the…
- risk 0.27cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of…
- risk 0.27cvss 4.2epss 0.02
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete…
- risk 0.27cvss 4.2epss 0.02
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a…
- risk 0.27cvss 4.1epss 0.02
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'.
- risk 0.27cvss 4.2epss 0.02
An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, in a…
- risk 0.27cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…
- risk 0.27cvss 4.2epss 0.01
A security feature bypass vulnerability exists when Windows Hyper-V BIOS loader fails to provide a high-entropy source, aka "Windows Hyper-V Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
- risk 0.27cvss 3.1epss 0.52
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
- risk 0.26cvss 4.0epss 0.00
Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security feature locally.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
- risk 0.26cvss 5.0epss 0.02
A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink following. It is…
- risk 0.26cvss 4.0epss 0.01
Azure CycleCloud Elevation of Privilege Vulnerability
- risk 0.26cvss 4.0epss 0.01
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. An authenticated attacker could…
- risk 0.25cvss 3.9epss 0.00
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
- risk 0.25cvss 3.9epss 0.01
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.25cvss 3.3epss 0.04
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
- risk 0.25cvss 3.3epss 0.03
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
- risk 0.25cvss 3.1epss 0.21
Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure…
- risk 0.24cvss 4.7epss 0.00
Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This vulnerability affects confidential client applications,…
- risk 0.24cvss 3.7epss 0.01
Microsoft Edge (Chromium-based) Tampering Vulnerability
- risk 0.24cvss 3.7epss 0.01
Microsoft Power BI Spoofing Vulnerability
- risk 0.24cvss 3.7epss 0.02
A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft Visual Studio Spoofing Vulnerability'.
- risk 0.24cvss 3.7epss 0.05
A security feature bypass vulnerability exists in Windows 10 1607, Windows Server 2012 R2, and Windows 2016 when ADFS incorrectly treats requests coming from Extranet clients as Intranet requests, aka "ADFS Security Feature Bypass Vulnerability."
- risk 0.23cvss 3.5epss 0.01
External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.
- risk 0.23cvss 3.5epss 0.04
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is…
- risk 0.23cvss 3.3epss 0.04
The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for…
- risk 0.23cvss 3.1epss 0.29
Windows Media Player in Microsoft Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; Windows 7 SP1; Windows 2008 SP2 and R2 SP1, Windows Server 2016; Windows Vista SP2; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted…
Page 217 of 314