VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2026-47290HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-58640HigJul 14, 2026
    risk 0.00cvss 7.3epss 0.00

    Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

  • CVE-2026-58636HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58635HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58631HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

  • CVE-2026-58618HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-58614MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-58610HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

  • CVE-2026-58609HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

  • CVE-2026-58608HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.

  • CVE-2026-58602HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58601HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58595HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-58526HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58279MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-57979MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-57976MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

  • CVE-2026-57969HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-57107HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.

  • CVE-2026-57097MedJul 14, 2026
    risk 0.00cvss 6.4epss 0.01

    Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2026-56193HigJul 14, 2026
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

  • CVE-2026-56185MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.

  • CVE-2026-56169HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-55948HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-55899HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-55144HigJul 14, 2026
    risk 0.00cvss 7.1epss 0.00

    Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.

  • CVE-2026-55014HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55012HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.

  • CVE-2026-55011HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.

  • CVE-2026-55009HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.03

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55008CriJul 14, 2026
    risk 0.00cvss 9.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-55006HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55005HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

  • CVE-2026-55004HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55003MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-55002HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-55001HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55000MedJul 14, 2026
    risk 0.00cvss 6.4epss 0.00

    Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

  • CVE-2026-54999HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2026-54997MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.

  • CVE-2026-54996HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-54995HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-54993HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.

  • CVE-2026-54992HigJul 14, 2026
    risk 0.00cvss 8.4epss 0.00

    Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.

  • CVE-2026-54991HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-54990CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.01

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-54989HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-54988MedJul 14, 2026
    risk 0.00cvss 6.1epss 0.00

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-54987HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

  • CVE-2026-54986HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

Page 297 of 314