Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-36958 | Hig | 0.53 | 7.8 | 0.31 | Aug 12, 2021 | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;… | ||
| CVE-2021-34524 | Hig | 0.53 | 8.1 | 0.04 | Aug 12, 2021 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | ||
| CVE-2021-34520 | Hig | 0.53 | 8.1 | 0.04 | Jul 14, 2021 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2021-34492 | Hig | 0.53 | 8.1 | 0.02 | Jul 14, 2021 | Windows Certificate Spoofing Vulnerability | ||
| CVE-2021-33786 | Hig | 0.53 | 8.1 | 0.02 | Jul 14, 2021 | Windows LSA Security Feature Bypass Vulnerability | ||
| CVE-2021-33781 | Hig | 0.53 | 8.1 | 0.02 | Jul 14, 2021 | Azure AD Security Feature Bypass Vulnerability | ||
| CVE-2021-33779 | Hig | 0.53 | 8.1 | 0.02 | Jul 14, 2021 | Windows AD FS Security Feature Bypass Vulnerability | ||
| CVE-2021-33767 | Hig | 0.53 | 8.2 | 0.01 | Jul 14, 2021 | Open Enclave SDK Elevation of Privilege Vulnerability | ||
| CVE-2021-31980 | Hig | 0.53 | 8.1 | 0.03 | Jun 8, 2021 | Microsoft Intune Management Extension Remote Code Execution Vulnerability | ||
| CVE-2021-31950 | Hig | 0.53 | 7.6 | 0.05 | Jun 8, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-28460 | Hig | 0.53 | 8.1 | 0.00 | Apr 13, 2021 | Azure Sphere Unsigned Code Execution Vulnerability | ||
| CVE-2021-28445 | Hig | 0.53 | 8.1 | 0.03 | Apr 13, 2021 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2021-24112 | Hig | 0.53 | 8.1 | 0.03 | Feb 25, 2021 | .NET Core Remote Code Execution Vulnerability | ||
| CVE-2021-24086 | Hig | 0.53 | 7.5 | 0.59 | Feb 25, 2021 | Windows TCP/IP Denial of Service Vulnerability | ||
| CVE-2021-1722 | Hig | 0.53 | 8.1 | 0.02 | Feb 25, 2021 | Windows Fax Service Remote Code Execution Vulnerability | ||
| CVE-2021-21125 | Hig | 0.53 | 8.1 | 0.08 | Feb 9, 2021 | Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | ||
| CVE-2020-17118 | Hig | 0.53 | 8.1 | 0.04 | Dec 10, 2020 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2020-16970 | Hig | 0.53 | 8.1 | 0.01 | Nov 11, 2020 | Azure Sphere Unsigned Code Execution Vulnerability | ||
| CVE-2020-1400 | Hig | 0.53 | 7.8 | 0.24 | Jul 14, 2020 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1401, CVE-2020-1407. | ||
| CVE-2020-1349 | Hig | 0.53 | 7.8 | 0.23 | Jul 14, 2020 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'. | ||
| CVE-2020-1022 | Hig | 0.53 | 8.0 | 0.07 | Apr 15, 2020 | A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | ||
| CVE-2020-0905 | Hig | 0.53 | 8.0 | 0.11 | Mar 12, 2020 | An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | ||
| CVE-2020-0692 | Hig | 0.53 | 8.1 | 0.03 | Feb 11, 2020 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. | ||
| CVE-2020-0665 | Hig | 0.53 | 8.1 | 0.04 | Feb 11, 2020 | An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'. | ||
| CVE-2019-1448 | Hig | 0.53 | 7.8 | 0.28 | Nov 12, 2019 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | ||
| CVE-2019-1424 | Hig | 0.53 | 8.1 | 0.03 | Nov 12, 2019 | A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'. | ||
| CVE-2019-1234 | Hig | 0.53 | 7.5 | 0.74 | Nov 12, 2019 | A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'. | ||
| CVE-2019-1311 | Hig | 0.53 | 7.8 | 0.36 | Oct 10, 2019 | A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'. | ||
| CVE-2019-1136 | Hig | 0.53 | 8.1 | 0.03 | Jul 15, 2019 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. | ||
| CVE-2019-0734 | Hig | 0.53 | 8.1 | 0.05 | May 16, 2019 | An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this… | ||
| CVE-2019-0728 | Hig | 0.53 | 7.8 | 0.24 | Mar 5, 2019 | A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vulnerability'. | ||
| CVE-2018-8587 | Hig | 0.53 | 7.8 | 0.30 | Dec 12, 2018 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. | ||
| CVE-2018-12368 | Hig | 0.53 | 8.1 | 0.04 | Oct 18, 2018 | Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web." Without the warning, unsuspecting users unfamiliar with this new file type might run an… | ||
| CVE-2018-8495 | Hig | 0.53 | 7.5 | 0.47 | Oct 10, 2018 | A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | ||
| CVE-2018-8423 | Hig | 0.53 | 7.8 | 0.28 | Oct 10, 2018 | A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server… | ||
| CVE-2018-8430 | Hig | 0.53 | 7.8 | 0.20 | Sep 13, 2018 | A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted PDF file, aka "Word PDF Remote Code Execution Vulnerability." This affects Microsoft Word, Microsoft Office. | ||
| CVE-2018-8392 | Hig | 0.53 | 7.8 | 0.21 | Sep 13, 2018 | A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | ||
| CVE-2018-8172 | Hig | 0.53 | 7.8 | 0.31 | Jul 11, 2018 | A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expression Blend 4. | ||
| CVE-2018-8210 | Hig | 0.53 | 7.8 | 0.31 | Jun 14, 2018 | A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10… | ||
| CVE-2018-8162 | Hig | 0.53 | 7.8 | 0.22 | May 9, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from… | ||
| CVE-2018-8158 | Hig | 0.53 | 7.8 | 0.22 | May 9, 2018 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-8157,… | ||
| CVE-2018-8157 | Hig | 0.53 | 7.8 | 0.22 | May 9, 2018 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-8158,… | ||
| CVE-2018-8148 | Hig | 0.53 | 7.8 | 0.22 | May 9, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from… | ||
| CVE-2018-8147 | Hig | 0.53 | 7.8 | 0.22 | May 9, 2018 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from… | ||
| CVE-2018-1003 | Hig | 0.53 | 7.8 | 0.21 | Apr 12, 2018 | A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,… | ||
| CVE-2018-0812 | Hig | 0.53 | 7.8 | 0.23 | Jan 10, 2018 | Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Memory Corruption… | ||
| CVE-2018-0797 | Hig | 0.53 | 7.8 | 0.23 | Jan 10, 2018 | Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability". | ||
| CVE-2017-11932 | Hig | 0.53 | 8.1 | 0.05 | Dec 12, 2017 | Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka "Microsoft Exchange Spoofing Vulnerability". | ||
| CVE-2017-11937 | Hig | 0.53 | 7.8 | 0.24 | Dec 7, 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and… | ||
| CVE-2017-8718 | Hig | 0.53 | 7.8 | 0.20 | Oct 13, 2017 | The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to take control of an affected system, due to how it handles… |
- risk 0.53cvss 7.8epss 0.31
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;…
- risk 0.53cvss 8.1epss 0.04
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.04
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.02
Windows Certificate Spoofing Vulnerability
- risk 0.53cvss 8.1epss 0.02
Windows LSA Security Feature Bypass Vulnerability
- risk 0.53cvss 8.1epss 0.02
Azure AD Security Feature Bypass Vulnerability
- risk 0.53cvss 8.1epss 0.02
Windows AD FS Security Feature Bypass Vulnerability
- risk 0.53cvss 8.2epss 0.01
Open Enclave SDK Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.03
Microsoft Intune Management Extension Remote Code Execution Vulnerability
- risk 0.53cvss 7.6epss 0.05
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.53cvss 8.1epss 0.00
Azure Sphere Unsigned Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.03
Windows Network File System Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.03
.NET Core Remote Code Execution Vulnerability
- risk 0.53cvss 7.5epss 0.59
Windows TCP/IP Denial of Service Vulnerability
- risk 0.53cvss 8.1epss 0.02
Windows Fax Service Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.08
Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.
- risk 0.53cvss 8.1epss 0.04
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Azure Sphere Unsigned Code Execution Vulnerability
- risk 0.53cvss 7.8epss 0.24
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1401, CVE-2020-1407.
- risk 0.53cvss 7.8epss 0.23
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.
- risk 0.53cvss 8.0epss 0.07
A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.
- risk 0.53cvss 8.0epss 0.11
An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.
- risk 0.53cvss 8.1epss 0.03
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
- risk 0.53cvss 8.1epss 0.04
An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.
- risk 0.53cvss 7.8epss 0.28
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
- risk 0.53cvss 8.1epss 0.03
A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'.
- risk 0.53cvss 7.5epss 0.74
A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.
- risk 0.53cvss 7.8epss 0.36
A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'.
- risk 0.53cvss 8.1epss 0.03
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
- risk 0.53cvss 8.1epss 0.05
An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this…
- risk 0.53cvss 7.8epss 0.24
A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vulnerability'.
- risk 0.53cvss 7.8epss 0.30
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.
- risk 0.53cvss 8.1epss 0.04
Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web." Without the warning, unsuspecting users unfamiliar with this new file type might run an…
- risk 0.53cvss 7.5epss 0.47
A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
- risk 0.53cvss 7.8epss 0.28
A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server…
- risk 0.53cvss 7.8epss 0.20
A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted PDF file, aka "Word PDF Remote Code Execution Vulnerability." This affects Microsoft Word, Microsoft Office.
- risk 0.53cvss 7.8epss 0.21
A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,…
- risk 0.53cvss 7.8epss 0.31
A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expression Blend 4.
- risk 0.53cvss 7.8epss 0.31
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10…
- risk 0.53cvss 7.8epss 0.22
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from…
- risk 0.53cvss 7.8epss 0.22
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-8157,…
- risk 0.53cvss 7.8epss 0.22
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-8158,…
- risk 0.53cvss 7.8epss 0.22
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from…
- risk 0.53cvss 7.8epss 0.22
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is unique from…
- risk 0.53cvss 7.8epss 0.21
A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1,…
- risk 0.53cvss 7.8epss 0.23
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Memory Corruption…
- risk 0.53cvss 7.8epss 0.23
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
- risk 0.53cvss 8.1epss 0.05
Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka "Microsoft Exchange Spoofing Vulnerability".
- risk 0.53cvss 7.8epss 0.24
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and…
- risk 0.53cvss 7.8epss 0.20
The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to take control of an affected system, due to how it handles…
Page 52 of 314