VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2016-0183HigMay 11, 2016
    risk 0.58cvss 8.8epss 0.16

    The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Microsoft Office Graphics RCE…

  • CVE-2016-0147HigApr 12, 2016
    risk 0.58cvss 8.8epss 0.16

    Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability."

  • CVE-2016-0068HigFeb 18, 2016
    risk 0.58cvss 8.8epss 0.15

    Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0069.

  • CVE-2016-0071HigFeb 10, 2016
    risk 0.58cvss 8.8epss 0.14

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

  • CVE-2016-0067HigFeb 10, 2016
    risk 0.58cvss 8.8epss 0.14

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060,…

  • CVE-2016-0064HigFeb 10, 2016
    risk 0.58cvss 8.8epss 0.14

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

  • CVE-2016-0015HigJan 13, 2016
    risk 0.58cvss 7.8epss 0.49

    DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "DirectShow Heap…

  • CVE-2016-0009HigJan 13, 2016
    risk 0.58cvss 8.8epss 0.15

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitrary code via unspecified vectors, aka "Win32k Remote Code Execution Vulnerability."

  • CVE-2011-1265HigJul 13, 2011
    risk 0.58cvss 8.8epss 0.06

    The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth…

  • CVE-2010-0820HigSep 15, 2010
    risk 0.58cvss 8.8epss 0.14

    Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2; Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server…

  • CVE-2007-4040HigJul 27, 2007
    risk 0.58cvss 8.8epss 0.13

    Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are…

  • CVE-2026-24301HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.02

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-73298HigAug 12, 2026
    risk 0.57cvss epss 0.01

    The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and earlier, a security vulnerability was…

  • CVE-2026-70337HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

  • CVE-2026-70336HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

  • CVE-2026-70329HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

  • CVE-2026-70326HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-70324HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-70321HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-69320HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

  • CVE-2026-66808HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-66805HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.02

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-65815HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

  • CVE-2026-65811HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper input validation in Power BI allows an authorized attacker to execute code over a network.

  • CVE-2026-65807HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

  • CVE-2026-65768HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.

  • CVE-2026-65767HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-65665HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.03

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-65663HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-65660HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-65658HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-64921HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-64901HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.02

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-63514HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.02

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-62913HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

  • CVE-2026-62872HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-62869HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-62827HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-62824HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62823HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2026-62822HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62818HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.

  • CVE-2026-62817HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2026-62816HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2026-62800HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.

  • CVE-2026-62795HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62790HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.

  • CVE-2026-62785HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62784HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.

  • CVE-2026-59133HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.

Page 25 of 314