VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2016-7200HigKEVNov 10, 2016
    risk 0.72cvss 8.8epss 0.82

    The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than…

  • CVE-2015-2546HigKEVSep 9, 2015
    risk 0.72cvss 8.2epss 0.11

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k…

  • CVE-2015-2424HigKEVJul 14, 2015
    risk 0.72cvss 8.8epss 0.39

    Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka…

  • CVE-2015-1770HigKEVJun 10, 2015
    risk 0.72cvss 8.8epss 0.35

    Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."

  • CVE-2015-0016HigKEVJan 13, 2015
    risk 0.72cvss 7.8epss 0.76

    Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain…

  • CVE-2014-6352HigKEVOct 22, 2014
    risk 0.72cvss 7.8epss 0.78

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October…

  • CVE-2014-4123HigKEVOct 15, 2014
    risk 0.72cvss 8.8epss 0.47

    Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.

  • CVE-2014-4114HigKEVOct 15, 2014
    risk 0.72cvss 7.8epss 0.82

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in…

  • CVE-2014-1761HigKEVMar 25, 2014
    risk 0.72cvss 7.8epss 0.77

    Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013…

  • CVE-2013-3906HigKEVNov 6, 2013
    risk 0.72cvss 7.8epss 0.85

    GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF image, as demonstrated…

  • CVE-2011-0657CriApr 13, 2011
    risk 0.72cvss 9.8epss 0.63

    DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote attackers to execute…

  • CVE-2026-55040CriKEVJul 14, 2026
    risk 0.71cvss 9.1epss 0.06

    Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-21510HigKEVFeb 10, 2026
    risk 0.71cvss 8.8epss 0.26

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2025-14174HigKEVDec 12, 2025
    risk 0.71cvss 8.8epss 0.23

    Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-49706MedKEVJul 8, 2025
    risk 0.71cvss 6.5epss 1.00

    Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2024-7965HigKEVAug 21, 2024
    risk 0.71cvss 8.8epss 0.19

    Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-24941CriMay 9, 2023
    risk 0.71cvss 9.8epss 0.95

    Windows Network File System Remote Code Execution Vulnerability

  • CVE-2022-41128HigKEVNov 9, 2022
    risk 0.71cvss 8.8epss 0.25

    Windows Scripting Languages Remote Code Execution Vulnerability

  • CVE-2022-26809CriApr 15, 2022
    risk 0.71cvss 9.8epss 0.91

    Remote Procedure Call Runtime Remote Code Execution Vulnerability

  • CVE-2022-21882HigKEVJan 11, 2022
    risk 0.71cvss 7.0epss 0.56

    Win32k Elevation of Privilege Vulnerability

  • CVE-2021-36934HigKEVJul 22, 2021
    risk 0.71cvss 7.8epss 0.67

    An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with…

  • CVE-2020-1040CriKEVJul 14, 2020
    risk 0.71cvss 9.0epss 0.07

    A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from…

  • CVE-2020-0674HigKEVFeb 11, 2020
    risk 0.71cvss 7.5epss 0.87

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712,…

  • CVE-2019-1367HigKEVSep 23, 2019
    risk 0.71cvss 7.5epss 0.53

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.

  • CVE-2019-1297HigKEVSep 11, 2019
    risk 0.71cvss 8.8epss 0.22

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.

  • CVE-2019-0903HigKEVMay 16, 2019
    risk 0.71cvss 8.8epss 0.22

    A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.

  • CVE-2017-8540HigKEVMay 26, 2017
    risk 0.71cvss 7.8epss 0.72

    The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server…

  • CVE-2017-0210HigKEVApr 12, 2017
    risk 0.71cvss 8.8epss 0.20

    An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege…

  • CVE-2016-0189HigKEVMay 11, 2016
    risk 0.71cvss 7.5epss 0.94

    The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine…

  • CVE-2016-0185HigKEVMay 11, 2016
    risk 0.71cvss 7.8epss 0.70

    Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."

  • CVE-2014-2817HigKEVAug 12, 2014
    risk 0.71cvss 8.8epss 0.26

    Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

  • CVE-2008-0081CriJan 16, 2008
    risk 0.71cvss 9.8epss 0.58

    Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.

  • CVE-2026-45659HigKEVMay 22, 2026
    risk 0.70cvss 8.8epss 0.76

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-42897HigKEVMay 14, 2026
    risk 0.70cvss 8.1epss 0.71

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-41089CriMay 12, 2026
    risk 0.70cvss 9.8epss 0.80

    Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

  • CVE-2026-21513HigKEVFeb 10, 2026
    risk 0.70cvss 8.8epss 0.15

    Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2025-5419HigKEVJun 3, 2025
    risk 0.70cvss 8.8epss 0.08

    Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-29824HigKEVApr 8, 2025
    risk 0.70cvss 7.8epss 0.14

    Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21298CriJan 14, 2025
    risk 0.70cvss 9.8epss 0.81

    Windows OLE Remote Code Execution Vulnerability

  • CVE-2024-38189HigKEVAug 13, 2024
    risk 0.70cvss 8.8epss 0.08

    Microsoft Project Remote Code Execution Vulnerability

  • CVE-2024-38077CriJul 9, 2024
    risk 0.70cvss 9.8epss 0.84

    Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

  • CVE-2024-30040HigKEVMay 14, 2024
    risk 0.70cvss 8.8epss 0.04

    Windows MSHTML Platform Security Feature Bypass Vulnerability

  • CVE-2023-38545CriOct 18, 2023
    risk 0.70cvss 9.8epss 0.78

    This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255…

  • CVE-2023-4863HigKEVSep 12, 2023
    risk 0.70cvss 8.8epss 1.00

    Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2023-35311HigKEVJul 11, 2023
    risk 0.70cvss 8.8epss 0.16

    Microsoft Outlook Security Feature Bypass Vulnerability

  • CVE-2023-32049HigKEVJul 11, 2023
    risk 0.70cvss 8.8epss 0.04

    Windows SmartScreen Security Feature Bypass Vulnerability

  • CVE-2023-23376HigKEVFeb 14, 2023
    risk 0.70cvss 7.8epss 0.11

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2023-21716CriFeb 14, 2023
    risk 0.70cvss 9.8epss 0.82

    Microsoft Word Remote Code Execution Vulnerability

  • CVE-2022-4135CriKEVNov 25, 2022
    risk 0.70cvss 9.6epss 0.32

    Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-34721CriSep 13, 2022
    risk 0.70cvss 9.8epss 0.79

    Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability

Page 4 of 314