Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-8670 | Hig | 0.57 | 7.5 | 0.56 | Aug 8, 2017 | Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting… | ||
| CVE-2017-8656 | Hig | 0.57 | 7.5 | 0.57 | Aug 8, 2017 | Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting… | ||
| CVE-2017-8646 | Hig | 0.57 | 7.5 | 0.57 | Aug 8, 2017 | Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine… | ||
| CVE-2017-8645 | Hig | 0.57 | 7.5 | 0.57 | Aug 8, 2017 | Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine… | ||
| CVE-2017-8641 | Hig | 0.57 | 7.5 | 0.59 | Aug 8, 2017 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to… | ||
| CVE-2017-8640 | Hig | 0.57 | 7.5 | 0.57 | Aug 8, 2017 | Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting… | ||
| CVE-2017-8634 | Hig | 0.57 | 7.5 | 0.58 | Aug 8, 2017 | Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption… | ||
| CVE-2017-8620 | Hig | 0.57 | 8.1 | 0.54 | Aug 8, 2017 | Windows Search in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it improperly handles objects in… | ||
| CVE-2017-8503 | Hig | 0.57 | 8.8 | 0.02 | Aug 8, 2017 | Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to escape from the AppContainer sandbox, aka "Microsoft Edge Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8642. | ||
| CVE-2017-8601 | Hig | 0.57 | 7.5 | 0.55 | Jul 11, 2017 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Edge, aka "Scripting… | ||
| CVE-2017-8590 | Hig | 0.57 | 8.8 | 0.01 | Jul 11, 2017 | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way that the Windows Common Log File… | ||
| CVE-2017-8558 | Hig | 0.57 | 7.8 | 0.43 | Jun 29, 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703… | ||
| CVE-2017-8548 | Hig | 0.57 | 7.5 | 0.55 | Jun 15, 2017 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system when Microsoft Edge improperly handles objects in memory, aka "Scripting Engine Memory Corruption… | ||
| CVE-2016-7288 | Hig | 0.57 | 7.5 | 0.68 | Dec 20, 2016 | The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7286, CVE-2016-7296,… | ||
| CVE-2016-7287 | Hig | 0.57 | 7.5 | 0.66 | Dec 20, 2016 | The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." | ||
| CVE-2016-7286 | Hig | 0.57 | 7.5 | 0.65 | Dec 20, 2016 | The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7288, CVE-2016-7296,… | ||
| CVE-2016-7241 | Hig | 0.57 | 7.5 | 0.71 | Nov 10, 2016 | Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." | ||
| CVE-2016-3298 | Med | 0.57 | 6.5 | 0.33 | KEV | Oct 14, 2016 | Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information… | |
| CVE-2016-3247 | Hig | 0.57 | 7.5 | 0.65 | Sep 14, 2016 | Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." | ||
| CVE-2016-3316 | Hig | 0.57 | 7.8 | 0.34 | Aug 9, 2016 | Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability." | ||
| CVE-2016-3301 | Hig | 0.57 | 7.8 | 0.35 | Aug 9, 2016 | The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync… | ||
| CVE-2016-3225 | Hig | 0.57 | 7.8 | 0.29 | Jun 16, 2016 | The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application that forwards an… | ||
| CVE-2016-3223 | Hig | 0.57 | 8.1 | 0.18 | Jun 16, 2016 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandle LDAP authentication, which allows man-in-the-middle attackers to gain privileges by modifying… | ||
| CVE-2016-0122 | Hig | 0.57 | 7.8 | 0.31 | Apr 12, 2016 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption… | ||
| CVE-2016-0117 | Hig | 0.57 | 7.8 | 0.76 | Mar 9, 2016 | The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows Remote Code Execution Vulnerability." | ||
| CVE-2015-0071 | Med | 0.57 | 6.5 | 0.34 | KEV | Feb 11, 2015 | Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability." | |
| CVE-2026-69558 | Hig | 0.56 | 8.6 | 0.01 | Aug 20, 2026 | Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-69519 | Hig | 0.56 | 8.6 | 0.01 | Aug 20, 2026 | Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-66800 | Hig | 0.56 | 8.6 | 0.01 | Aug 20, 2026 | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-35435 | Hig | 0.56 | 8.6 | 0.01 | May 7, 2026 | Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-26150 | Hig | 0.56 | 8.6 | 0.01 | Apr 23, 2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-32201 | Med | 0.56 | 6.5 | 0.43 | KEV | Apr 14, 2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2026-32173 | Hig | 0.56 | 8.6 | 0.01 | Apr 3, 2026 | Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-26139 | Hig | 0.56 | 8.6 | 0.01 | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-26138 | Hig | 0.56 | 8.6 | 0.01 | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-23659 | Hig | 0.56 | 8.6 | 0.01 | Mar 19, 2026 | Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-23658 | Hig | 0.56 | 8.6 | 0.01 | Mar 19, 2026 | Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-26125 | Hig | 0.56 | 8.6 | 0.01 | Mar 5, 2026 | Payment Orchestrator Service Elevation of Privilege Vulnerability | ||
| CVE-2026-24302 | Hig | 0.56 | 8.6 | 0.02 | Feb 5, 2026 | Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-62207 | Hig | 0.56 | 8.6 | 0.01 | Nov 20, 2025 | Azure Monitor Elevation of Privilege Vulnerability | ||
| CVE-2025-9491 | Hig | 0.56 | 7.8 | 0.69 | Aug 26, 2025 | Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target… | ||
| CVE-2025-48822 | Hig | 0.56 | 8.6 | 0.01 | Jul 8, 2025 | Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-27737 | Hig | 0.56 | 8.6 | 0.01 | Apr 8, 2025 | Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2025-21355 | Hig | 0.56 | 8.6 | 0.02 | Feb 19, 2025 | Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network | ||
| CVE-2024-38190 | Hig | 0.56 | 8.6 | 0.01 | Oct 15, 2024 | Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector. | ||
| CVE-2024-38206 | Hig | 0.56 | 8.5 | 0.12 | Aug 6, 2024 | An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. | ||
| CVE-2023-36563 | Med | 0.56 | 6.5 | 0.21 | KEV | Oct 10, 2023 | Microsoft WordPad Information Disclosure Vulnerability | |
| CVE-2023-36761 | Med | 0.56 | 6.5 | 0.19 | KEV | Sep 12, 2023 | Microsoft Word Information Disclosure Vulnerability | |
| CVE-2023-28302 | Hig | 0.56 | 7.5 | 0.93 | Apr 11, 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2023-28288 | Hig | 0.56 | 8.1 | 0.06 | Apr 11, 2023 | Microsoft SharePoint Server Spoofing Vulnerability |
- risk 0.57cvss 7.5epss 0.56
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting…
- risk 0.57cvss 7.5epss 0.57
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting…
- risk 0.57cvss 7.5epss 0.57
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine…
- risk 0.57cvss 7.5epss 0.57
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine…
- risk 0.57cvss 7.5epss 0.59
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to…
- risk 0.57cvss 7.5epss 0.57
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting…
- risk 0.57cvss 7.5epss 0.58
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption…
- risk 0.57cvss 8.1epss 0.54
Windows Search in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it improperly handles objects in…
- risk 0.57cvss 8.8epss 0.02
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to escape from the AppContainer sandbox, aka "Microsoft Edge Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8642.
- risk 0.57cvss 7.5epss 0.55
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Edge, aka "Scripting…
- risk 0.57cvss 8.8epss 0.01
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way that the Windows Common Log File…
- risk 0.57cvss 7.8epss 0.43
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703…
- risk 0.57cvss 7.5epss 0.55
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system when Microsoft Edge improperly handles objects in memory, aka "Scripting Engine Memory Corruption…
- risk 0.57cvss 7.5epss 0.68
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7286, CVE-2016-7296,…
- risk 0.57cvss 7.5epss 0.66
The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."
- risk 0.57cvss 7.5epss 0.65
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7288, CVE-2016-7296,…
- risk 0.57cvss 7.5epss 0.71
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
- risk 0.57cvss 6.5epss 0.33
Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information…
- risk 0.57cvss 7.5epss 0.65
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."
- risk 0.57cvss 7.8epss 0.34
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability."
- risk 0.57cvss 7.8epss 0.35
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync…
- risk 0.57cvss 7.8epss 0.29
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application that forwards an…
- risk 0.57cvss 8.1epss 0.18
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandle LDAP authentication, which allows man-in-the-middle attackers to gain privileges by modifying…
- risk 0.57cvss 7.8epss 0.31
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption…
- risk 0.57cvss 7.8epss 0.76
The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows Remote Code Execution Vulnerability."
- risk 0.57cvss 6.5epss 0.34
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
- risk 0.56cvss 8.6epss 0.01
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
- risk 0.56cvss 8.6epss 0.01
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
- risk 0.56cvss 8.6epss 0.01
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
- risk 0.56cvss 8.6epss 0.01
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.
- risk 0.56cvss 8.6epss 0.01
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
- risk 0.56cvss 6.5epss 0.43
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- risk 0.56cvss 8.6epss 0.01
Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
- risk 0.56cvss 8.6epss 0.01
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
- risk 0.56cvss 8.6epss 0.01
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
- risk 0.56cvss 8.6epss 0.01
Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
- risk 0.56cvss 8.6epss 0.01
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
- risk 0.56cvss 8.6epss 0.01
Payment Orchestrator Service Elevation of Privilege Vulnerability
- risk 0.56cvss 8.6epss 0.02
Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- risk 0.56cvss 8.6epss 0.01
Azure Monitor Elevation of Privilege Vulnerability
- risk 0.56cvss 7.8epss 0.69
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target…
- risk 0.56cvss 8.6epss 0.01
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
- risk 0.56cvss 8.6epss 0.01
Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.
- risk 0.56cvss 8.6epss 0.02
Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network
- risk 0.56cvss 8.6epss 0.01
Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.
- risk 0.56cvss 8.5epss 0.12
An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.
- risk 0.56cvss 6.5epss 0.21
Microsoft WordPad Information Disclosure Vulnerability
- risk 0.56cvss 6.5epss 0.19
Microsoft Word Information Disclosure Vulnerability
- risk 0.56cvss 7.5epss 0.93
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.56cvss 8.1epss 0.06
Microsoft SharePoint Server Spoofing Vulnerability
Page 40 of 314