Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-49735 | Hig | 0.53 | 8.1 | 0.01 | Jul 8, 2025 | Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-33054 | Hig | 0.53 | 8.1 | 0.01 | Jul 8, 2025 | Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-3052 | Hig | 0.53 | 8.2 | 0.00 | Jun 10, 2025 | An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting… | ||
| CVE-2025-47977 | Hig | 0.53 | 8.2 | 0.01 | Jun 10, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-33070 | Hig | 0.53 | 8.1 | 0.07 | Jun 10, 2025 | Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-32710 | Hig | 0.53 | 8.1 | 0.01 | Jun 10, 2025 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-29828 | Hig | 0.53 | 8.1 | 0.01 | Jun 10, 2025 | Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-29971 | Hig | 0.53 | 7.5 | 0.64 | May 13, 2025 | Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2025-33072 | Hig | 0.53 | 8.1 | 0.02 | May 8, 2025 | Improper access control in Azure allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-30391 | Hig | 0.53 | 8.1 | 0.01 | Apr 30, 2025 | Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-27482 | Hig | 0.53 | 8.1 | 0.02 | Apr 8, 2025 | Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-27480 | Hig | 0.53 | 8.1 | 0.12 | Apr 8, 2025 | Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-26671 | Hig | 0.53 | 8.1 | 0.01 | Apr 8, 2025 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-26670 | Hig | 0.53 | 8.1 | 0.10 | Apr 8, 2025 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-26663 | Hig | 0.53 | 8.1 | 0.02 | Apr 8, 2025 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-26683 | Hig | 0.53 | 8.1 | 0.01 | Mar 31, 2025 | Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-24064 | Hig | 0.53 | 8.1 | 0.01 | Mar 11, 2025 | Use after free in DNS Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-24045 | Hig | 0.53 | 8.1 | 0.01 | Mar 11, 2025 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-24035 | Hig | 0.53 | 8.1 | 0.02 | Mar 11, 2025 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-21376 | Hig | 0.53 | 8.1 | 0.09 | Feb 11, 2025 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2025-21396 | Hig | 0.53 | 8.2 | 0.01 | Jan 29, 2025 | Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-21297 | Hig | 0.53 | 8.1 | 0.01 | Jan 14, 2025 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2025-21295 | Hig | 0.53 | 8.1 | 0.02 | Jan 14, 2025 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | ||
| CVE-2025-21294 | Hig | 0.53 | 8.1 | 0.01 | Jan 14, 2025 | Microsoft Digest Authentication Remote Code Execution Vulnerability | ||
| CVE-2025-21285 | Hig | 0.53 | 7.5 | 0.56 | Jan 14, 2025 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2025-21224 | Hig | 0.53 | 8.1 | 0.02 | Jan 14, 2025 | Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | ||
| CVE-2024-49132 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49128 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2024-49127 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2024-49126 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | ||
| CVE-2024-49124 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability | ||
| CVE-2024-49123 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49120 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49119 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49118 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2024-49116 | Hig | 0.53 | 8.1 | 0.10 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49115 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49108 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49106 | Hig | 0.53 | 8.1 | 0.01 | Dec 12, 2024 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49068 | Hig | 0.53 | 8.2 | 0.02 | Dec 12, 2024 | Microsoft SharePoint Elevation of Privilege Vulnerability | ||
| CVE-2024-49057 | Hig | 0.53 | 8.1 | 0.02 | Dec 12, 2024 | Microsoft Defender for Endpoint on Android Spoofing Vulnerability | ||
| CVE-2024-49052 | Hig | 0.53 | 8.2 | 0.01 | Nov 26, 2024 | Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2024-43625 | Hig | 0.53 | 8.1 | 0.01 | Nov 12, 2024 | Microsoft Windows VMSwitch Elevation of Privilege Vulnerability | ||
| CVE-2024-43598 | Hig | 0.53 | 8.1 | 0.01 | Nov 12, 2024 | LightGBM Remote Code Execution Vulnerability | ||
| CVE-2024-43447 | Hig | 0.53 | 8.1 | 0.01 | Nov 12, 2024 | Windows SMBv3 Server Remote Code Execution Vulnerability | ||
| CVE-2024-43582 | Hig | 0.53 | 8.1 | 0.03 | Oct 8, 2024 | Remote Desktop Protocol Server Remote Code Execution Vulnerability | ||
| CVE-2024-38229 | Hig | 0.53 | 8.1 | 0.02 | Oct 8, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2024-43460 | Hig | 0.53 | 8.1 | 0.01 | Sep 17, 2024 | Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network. | ||
| CVE-2024-38240 | Hig | 0.53 | 8.1 | 0.01 | Sep 10, 2024 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | ||
| CVE-2024-38216 | Hig | 0.53 | 8.2 | 0.01 | Sep 10, 2024 | Azure Stack Hub Elevation of Privilege Vulnerability |
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 8.2epss 0.00
An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting…
- risk 0.53cvss 8.2epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 8.1epss 0.07
Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 7.5epss 0.64
Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network.
- risk 0.53cvss 8.1epss 0.02
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.
- risk 0.53cvss 8.1epss 0.01
Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.
- risk 0.53cvss 8.1epss 0.02
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.12
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.10
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.02
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.01
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.02
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.09
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.2epss 0.01
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.02
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Microsoft Digest Authentication Remote Code Execution Vulnerability
- risk 0.53cvss 7.5epss 0.56
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.53cvss 8.1epss 0.02
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.10
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.53cvss 8.2epss 0.02
Microsoft SharePoint Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.02
Microsoft Defender for Endpoint on Android Spoofing Vulnerability
- risk 0.53cvss 8.2epss 0.01
Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.01
Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.01
LightGBM Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Windows SMBv3 Server Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.03
Remote Desktop Protocol Server Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.02
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.01
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
- risk 0.53cvss 8.2epss 0.01
Azure Stack Hub Elevation of Privilege Vulnerability
Page 49 of 314