Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2008-4835 | Cri | 0.67 | 9.8 | 0.45 | Jan 14, 2009 | SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request,… | ||
| CVE-2025-55315 | Cri | 0.66 | 9.9 | 0.66 | Oct 14, 2025 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. | ||
| CVE-2025-21333 | Hig | 0.66 | 7.8 | 0.10 | KEV | Jan 14, 2025 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | |
| CVE-2023-5217 | Hig | 0.66 | 8.8 | 0.49 | KEV | Sep 28, 2023 | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2023-21690 | Cri | 0.66 | 9.8 | 0.28 | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | ||
| CVE-2023-21689 | Cri | 0.66 | 9.8 | 0.27 | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | ||
| CVE-2022-24497 | Cri | 0.66 | 9.8 | 0.35 | Apr 15, 2022 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2022-24491 | Cri | 0.66 | 9.8 | 0.33 | Apr 15, 2022 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2021-24074 | Cri | 0.66 | 9.8 | 0.26 | Feb 25, 2021 | Windows TCP/IP Remote Code Execution Vulnerability | ||
| CVE-2021-1647 | Hig | 0.66 | 7.8 | 0.39 | KEV | Jan 12, 2021 | Microsoft Defender Remote Code Execution Vulnerability | |
| CVE-2020-16009 | Hig | 0.66 | 8.8 | 0.49 | KEV | Nov 3, 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2020-1464 | Hig | 0.66 | 7.8 | 0.41 | KEV | Aug 17, 2020 | A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features… | |
| CVE-2020-0683 | Hig | 0.66 | 7.8 | 0.08 | KEV | Feb 11, 2020 | An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686. | |
| CVE-2019-1372 | Cri | 0.66 | 10.0 | 0.19 | Oct 10, 2019 | An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to… | ||
| CVE-2019-1132 | Hig | 0.66 | 7.8 | 0.10 | KEV | Jul 15, 2019 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. | |
| CVE-2019-0863 | Hig | 0.66 | 7.8 | 0.05 | KEV | May 16, 2019 | An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. | |
| CVE-2019-0725 | Cri | 0.66 | 9.8 | 0.26 | May 16, 2019 | A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'. | ||
| CVE-2019-0697 | Cri | 0.66 | 9.8 | 0.33 | Apr 9, 2019 | A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726. | ||
| CVE-2018-8421 | Cri | 0.66 | 9.8 | 0.29 | Sep 13, 2018 | A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2,… | ||
| CVE-2018-8373 | Hig | 0.66 | 7.5 | 0.62 | KEV | Aug 15, 2018 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is… | |
| CVE-2018-8302 | Cri | 0.66 | 9.8 | 0.26 | Aug 15, 2018 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. | ||
| CVE-2018-8273 | Cri | 0.66 | 9.8 | 0.29 | Aug 15, 2018 | A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server. | ||
| CVE-2018-12571 | Cri | 0.66 | 9.8 | 0.30 | Jul 5, 2018 | uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or… | ||
| CVE-2017-8686 | Cri | 0.66 | 9.8 | 0.28 | Sep 13, 2017 | The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows… | ||
| CVE-2017-8589 | Cri | 0.66 | 9.8 | 0.26 | Jul 11, 2017 | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in… | ||
| CVE-2016-3227 | Cri | 0.66 | 9.8 | 0.25 | Jun 16, 2016 | Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability." | ||
| CVE-2016-3213 | Hig | 0.66 | 8.8 | 0.67 | Jun 16, 2016 | The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 9 through 11 has an… | ||
| CVE-2016-0003 | Cri | 0.66 | 9.6 | 0.38 | Jan 13, 2016 | Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Microsoft Edge Memory Corruption Vulnerability." | ||
| CVE-2015-2387 | Hig | 0.66 | 7.8 | 0.35 | KEV | Jul 14, 2015 | ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges… | |
| CVE-2012-1891 | Cri | 0.66 | 9.8 | 0.29 | Jul 10, 2012 | Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO… | ||
| CVE-2010-4398 | Hig | 0.66 | 7.8 | 0.09 | KEV | Dec 6, 2010 | Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the… | |
| CVE-2009-2512 | Cri | 0.66 | 9.8 | 0.31 | Nov 11, 2009 | The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, aka "Web Services… | ||
| CVE-2004-0210 | Hig | 0.66 | 7.8 | 0.07 | KEV | Aug 6, 2004 | The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow. | |
| CVE-2002-0367 | Hig | 0.66 | 7.8 | 0.05 | KEV | Jun 25, 2002 | smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit. | |
| CVE-2026-69502 | Cri | 0.65 | 10.0 | 0.01 | Aug 21, 2026 | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-69836 | Cri | 0.65 | 10.0 | 0.02 | Aug 20, 2026 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69555 | Cri | 0.65 | 10.0 | 0.00 | Aug 20, 2026 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-65816 | Cri | 0.65 | 10.0 | 0.01 | Aug 20, 2026 | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-65801 | Cri | 0.65 | 10.0 | 0.01 | Aug 20, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-65770 | Cri | 0.65 | 10.0 | 0.01 | Aug 20, 2026 | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-65667 | Cri | 0.65 | 10.0 | 0.01 | Aug 7, 2026 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-63508 | Cri | 0.65 | 10.0 | 0.01 | Aug 7, 2026 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-56162 | Cri | 0.65 | 10.0 | 0.01 | Aug 7, 2026 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-58630 | Cri | 0.65 | 10.0 | 0.00 | Jul 24, 2026 | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-62825 | Cri | 0.65 | 10.0 | 0.01 | Jul 24, 2026 | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-58275 | Cri | 0.65 | 10.0 | 0.01 | Jul 24, 2026 | Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-45480 | Cri | 0.65 | 10.0 | 0.01 | Jun 19, 2026 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-48567 | Cri | 0.65 | 10.0 | 0.01 | Jun 4, 2026 | Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-47280 | Cri | 0.65 | 10.0 | 0.00 | May 22, 2026 | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-42901 | Cri | 0.65 | 10.0 | 0.00 | May 22, 2026 | Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. |
- risk 0.67cvss 9.8epss 0.45
SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request,…
- risk 0.66cvss 9.9epss 0.66
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
- risk 0.66cvss 7.8epss 0.10
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
- risk 0.66cvss 8.8epss 0.49
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.66cvss 9.8epss 0.28
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.27
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.35
Windows Network File System Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.33
Windows Network File System Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.26
Windows TCP/IP Remote Code Execution Vulnerability
- risk 0.66cvss 7.8epss 0.39
Microsoft Defender Remote Code Execution Vulnerability
- risk 0.66cvss 8.8epss 0.49
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.66cvss 7.8epss 0.41
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features…
- risk 0.66cvss 7.8epss 0.08
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.
- risk 0.66cvss 10.0epss 0.19
An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to…
- risk 0.66cvss 7.8epss 0.10
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
- risk 0.66cvss 7.8epss 0.05
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
- risk 0.66cvss 9.8epss 0.26
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
- risk 0.66cvss 9.8epss 0.33
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726.
- risk 0.66cvss 9.8epss 0.29
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2,…
- risk 0.66cvss 7.5epss 0.62
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is…
- risk 0.66cvss 9.8epss 0.26
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.
- risk 0.66cvss 9.8epss 0.29
A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.
- risk 0.66cvss 9.8epss 0.30
uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or…
- risk 0.66cvss 9.8epss 0.28
The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows…
- risk 0.66cvss 9.8epss 0.26
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in…
- risk 0.66cvss 9.8epss 0.25
Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability."
- risk 0.66cvss 8.8epss 0.67
The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 9 through 11 has an…
- risk 0.66cvss 9.6epss 0.38
Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Microsoft Edge Memory Corruption Vulnerability."
- risk 0.66cvss 7.8epss 0.35
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges…
- risk 0.66cvss 9.8epss 0.29
Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO…
- risk 0.66cvss 7.8epss 0.09
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the…
- risk 0.66cvss 9.8epss 0.31
The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, aka "Web Services…
- risk 0.66cvss 7.8epss 0.07
The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
- risk 0.66cvss 7.8epss 0.05
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.
- risk 0.65cvss 10.0epss 0.01
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.02
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 10.0epss 0.00
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 10.0epss 0.01
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.00
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.00
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.00
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Page 7 of 314