VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-1999-0253Jan 1, 1997
    risk 0.01cvss epss 0.08

    IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.

  • CVE-2026-66803CriJul 30, 2026
    risk 0.00cvss 10.0epss 0.01

    Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

  • CVE-2026-57990HigJul 26, 2026
    risk 0.00cvss 7.4epss 0.01

    Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-57989HigJul 26, 2026
    risk 0.00cvss 7.4epss 0.00

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-57978MedJul 26, 2026
    risk 0.00cvss 5.4epss 0.00

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-62835CriJul 24, 2026
    risk 0.00cvss 9.3epss 0.01

    Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-57106CriJul 24, 2026
    risk 0.00cvss 10.0epss 0.00

    Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-56163CriJul 24, 2026
    risk 0.00cvss 10.0epss 0.00

    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-56191CriJul 24, 2026
    risk 0.00cvss 10.0epss 0.01

    Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-56167HigJul 24, 2026
    risk 0.00cvss 8.5epss 0.00

    Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-56165CriJul 24, 2026
    risk 0.00cvss 9.8epss 0.01

    Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

  • CVE-2026-50517CriJul 24, 2026
    risk 0.00cvss 9.9epss 0.01

    Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

  • CVE-2026-49159MedJul 24, 2026
    risk 0.00cvss 6.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

  • CVE-2025-66390CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.01

    In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup…

  • CVE-2026-57980MedJul 17, 2026
    risk 0.00cvss 5.4epss 0.00

    Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-56171HigJul 17, 2026
    risk 0.00cvss 7.1epss 0.01

    Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-62826MedJul 16, 2026
    risk 0.00cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-59117HigJul 16, 2026
    risk 0.00cvss 7.5epss 0.01

    Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58598HigJul 16, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

  • CVE-2026-57206HigJul 16, 2026
    risk 0.00cvss 8.6epss 0.01

    SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST…

  • CVE-2026-57205MedJul 16, 2026
    risk 0.00cvss 4.3epss 0.01

    SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in…

  • CVE-2026-55440MedJul 16, 2026
    risk 0.00cvss 6.5epss 0.01

    Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, allowing an…

  • CVE-2026-54733CriJul 16, 2026
    risk 0.00cvss epss 0.01

    The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT…

  • CVE-2026-54568MedJul 16, 2026
    risk 0.00cvss 4.3epss 0.01

    Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id and receive that device's server-side…

  • CVE-2026-61371HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.01

    Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target. The destructive effect is performed at open-time via O_TRUNC, and can happen before full input validation completes…

  • CVE-2026-47305HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.

  • CVE-2026-47301HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-58638MedJul 14, 2026
    risk 0.00cvss 6.0epss 0.00

    Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-58637HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58634HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58633HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58632HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58629HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58628HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58627HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

  • CVE-2026-58626HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

  • CVE-2026-58619HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58617HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-58613HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58594HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58547MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58546MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-58545MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-58544HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58543MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.

  • CVE-2026-58542HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

  • CVE-2026-58541HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58540HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58539MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-58538HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

Page 289 of 314