VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2026-45496MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-44806MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.01

    Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

  • CVE-2026-44800HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42990CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.01

    Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42982HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

  • CVE-2026-42975HigJul 14, 2026
    risk 0.00cvss 8.0epss 0.01

    Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2026-42900HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-41087MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-40422MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-40400HigJul 14, 2026
    risk 0.00cvss 8.0epss 0.01

    Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

  • CVE-2026-40378HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

  • CVE-2026-34349MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

  • CVE-2026-34348MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

  • CVE-2026-34346MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

  • CVE-2026-34328MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

  • CVE-2026-33842MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

  • CVE-2026-58596HigJul 12, 2026
    risk 0.00cvss 8.3epss 0.01

    Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-58281HigJul 11, 2026
    risk 0.00cvss 8.3epss 0.01

    Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-57476MedJul 10, 2026
    risk 0.00cvss 4.8epss 0.00

    Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network…

  • CVE-2026-57475MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.01

    Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI Assist for Customer restricted…

  • CVE-2026-57474MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.01

    Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist for Customer restricted network…

  • CVE-2026-47646CriJul 9, 2026
    risk 0.00cvss 9.3epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-58525HigJul 8, 2026
    risk 0.00cvss 8.2epss 0.00

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-58523MedJul 3, 2026
    risk 0.00cvss 6.5epss 0.01

    Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-58597MedJul 3, 2026
    risk 0.00cvss 4.3epss 0.01

    Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-58524MedJul 3, 2026
    risk 0.00cvss 5.4epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-58522MedJul 3, 2026
    risk 0.00cvss 6.8epss 0.00

    Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

  • CVE-2026-58300MedJul 3, 2026
    risk 0.00cvss 6.2epss 0.00

    Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

  • CVE-2026-58299HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58298HigJul 3, 2026
    risk 0.00cvss 7.2epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-58297HigJul 3, 2026
    risk 0.00cvss 7.1epss 0.01

    Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-58296HigJul 3, 2026
    risk 0.00cvss 7.1epss 0.01

    Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-58295HigJul 3, 2026
    risk 0.00cvss 8.3epss 0.01

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-58294HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.01

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58293HigJul 3, 2026
    risk 0.00cvss 8.1epss 0.01

    External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58292HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58291MedJul 3, 2026
    risk 0.00cvss 6.1epss 0.01

    Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-58290HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58289CriJul 3, 2026
    risk 0.00cvss 9.0epss 0.02

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58288HigJul 3, 2026
    risk 0.00cvss 8.3epss 0.01

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58287HigJul 3, 2026
    risk 0.00cvss 8.3epss 0.01

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58286HigJul 3, 2026
    risk 0.00cvss 8.1epss 0.00

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-58285HigJul 3, 2026
    risk 0.00cvss 8.3epss 0.01

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58284HigJul 3, 2026
    risk 0.00cvss 8.3epss 0.01

    Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-58283HigJul 3, 2026
    risk 0.00cvss 8.1epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-58282HigJul 3, 2026
    risk 0.00cvss 8.1epss 0.00

    Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-58278MedJul 3, 2026
    risk 0.00cvss 5.4epss 0.00

    Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-58276HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.01

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-57993HigJul 3, 2026
    risk 0.00cvss 7.4epss 0.01

    Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-57992HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.01

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Page 300 of 314