VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2026-57991HigJul 3, 2026
    risk 0.00cvss 7.4epss 0.01

    Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-57988HigJul 3, 2026
    risk 0.00cvss 7.1epss 0.01

    Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-57987MedJul 3, 2026
    risk 0.00cvss 6.5epss 0.01

    Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-57986HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.01

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-57985HigJul 3, 2026
    risk 0.00cvss 7.6epss 0.01

    Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-57984HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.01

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-57983HigJul 3, 2026
    risk 0.00cvss 8.7epss 0.01

    Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-57981HigJul 3, 2026
    risk 0.00cvss 8.8epss 0.01

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-57977HigJul 3, 2026
    risk 0.00cvss 7.1epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-57975HigJul 3, 2026
    risk 0.00cvss 7.5epss 0.01

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-57974HigJul 3, 2026
    risk 0.00cvss 8.8epss 0.01

    Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-56646MedJul 3, 2026
    risk 0.00cvss 6.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-56645HigJul 3, 2026
    risk 0.00cvss 8.8epss 0.01

    Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-55945MedJul 3, 2026
    risk 0.00cvss 4.2epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

  • CVE-2026-45489MedJul 3, 2026
    risk 0.00cvss 6.5epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2026-45488MedJul 3, 2026
    risk 0.00cvss 5.4epss 0.00

    User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-57100CriJul 2, 2026
    risk 0.00cvss 9.9epss 0.01

    Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-54998HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.01

    Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-45499CriJul 2, 2026
    risk 0.00cvss 9.9epss 0.01

    Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-41106CriJul 2, 2026
    risk 0.00cvss 9.3epss 0.01

    Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-26145MedJul 2, 2026
    risk 0.00cvss 4.8epss 0.01

    Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-50521HigJul 1, 2026
    risk 0.00cvss 8.3epss 0.00

    Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

  • CVE-2026-49451HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.01

    The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extract raw OpenAPI JSON and YAML documents from the model. From 2.0.0-preview11 until 2.7.5 and 3.5.4, a small OpenAPI document containing a circular schema…

  • CVE-2023-37524HigJun 27, 2026
    risk 0.00cvss 7.7epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service.  Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security…

  • CVE-2024-54138MedDec 6, 2024
    risk 0.00cvss 6.1epss 0.00

    NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately sanitize autolinks.…

  • CVE-2024-47604HigOct 1, 2024
    risk 0.00cvss 8.2epss 0.01

    NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser.

  • CVE-2024-37304MedJun 12, 2024
    risk 0.00cvss 6.1epss 0.01

    NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately sanitize autolinks.…

  • CVE-2017-20190Mar 27, 2024
    risk 0.00cvss epss 0.00

    Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third parties dispute whether the computational cost of interpreting…

  • CVE-2024-29195MedMar 26, 2024
    risk 0.00cvss 6.0epss 0.05

    The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocation or heap buffer…

  • CVE-2024-27099CriFeb 27, 2024
    risk 0.00cvss 9.8epss 0.01

    The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987.

  • CVE-2024-21638CriJan 10, 2024
    risk 0.00cvss 9.1epss 0.02

    Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP Address space easily and effectively. By design there is no write access to customers' Azure environments as the Service Principal…

  • CVE-2024-21646CriJan 9, 2024
    risk 0.00cvss 9.8epss 0.05

    Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When clients using this library receive a crafted binary type data, an integer overflow or wraparound or memory safety issue can occur…

  • CVE-2021-23338MedFeb 15, 2021
    risk 0.00cvss 6.6epss 0.04

    This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.

  • CVE-2020-8567MedJan 21, 2021
    risk 0.00cvss 4.9epss 0.01

    Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including…

  • CVE-2020-17131MedDec 10, 2020
    risk 0.00cvss 4.2epss 0.02

    Chakra Scripting Engine Memory Corruption Vulnerability

  • CVE-2020-26233HigDec 8, 2020
    risk 0.00cvss 7.3epss 0.06

    Git Credential Manager Core (GCM Core) is a secure Git credential helper built on .NET Core that runs on Windows and macOS. In Git Credential Manager Core before version 2.0.289, when recursively cloning a Git repository on Windows with submodules, Git will first clone the…

  • CVE-2020-17054MedNov 11, 2020
    risk 0.00cvss 4.2epss 0.02

    Chakra Scripting Engine Memory Corruption Vulnerability

  • CVE-2020-17048MedNov 11, 2020
    risk 0.00cvss 4.2epss 0.02

    Chakra Scripting Engine Memory Corruption Vulnerability

  • CVE-2020-1180MedSep 11, 2020
    risk 0.00cvss 4.2epss 0.02

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who…

  • CVE-2020-1172MedSep 11, 2020
    risk 0.00cvss 4.2epss 0.02

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who…

  • CVE-2020-1057MedSep 11, 2020
    risk 0.00cvss 4.2epss 0.02

    A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who…

  • CVE-2020-0813HigMar 12, 2020
    risk 0.00cvss 7.5epss 0.05

    An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user’s computer or data.To exploit the vulnerability, an attacker must know the memory…

  • CVE-2018-0818HigJan 10, 2018
    risk 0.00cvss 7.5epss 0.04

    Microsoft ChakraCore allows an attacker to bypass Control Flow Guard (CFG) in conjunction with another vulnerability to run arbitrary code on a target system, due to how the Chakra scripting engine handles accessing memory, aka "Scripting Engine Security Feature Bypass".

  • CVE-2015-6126Dec 9, 2015
    risk 0.00cvss epss 0.02

    Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511…

  • CVE-2015-6113Nov 11, 2015
    risk 0.00cvss epss 0.02

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass intended filesystem permissions by leveraging…

  • CVE-2015-6112Nov 11, 2015
    risk 0.00cvss epss 0.03

    SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's X.509 certificate…

  • CVE-2015-6109Nov 11, 2015
    risk 0.00cvss epss 0.03

    The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via a crafted application, aka "Windows Kernel Memory…

  • CVE-2015-6095Nov 11, 2015
    risk 0.00cvss epss 0.04

    Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles password changes, which allows physically proximate attackers to…

  • CVE-2015-2478Nov 11, 2015
    risk 0.00cvss epss 0.02

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application that triggers a Winsock…

  • CVE-2015-2552Oct 14, 2015
    risk 0.00cvss epss 0.02

    The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows physically proximate attackers to bypass the Trusted Boot protection mechanism, and consequently interfere with the integrity of code, BitLocker,…

Page 301 of 314