VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2008-4835CriJan 14, 2009
    risk 0.67cvss 9.8epss 0.45

    SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request,…

  • CVE-2025-55315CriOct 14, 2025
    risk 0.66cvss 9.9epss 0.66

    Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

  • CVE-2025-21333HigKEVJan 14, 2025
    risk 0.66cvss 7.8epss 0.10

    Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

  • CVE-2023-5217HigKEVSep 28, 2023
    risk 0.66cvss 8.8epss 0.49

    Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-21690CriFeb 14, 2023
    risk 0.66cvss 9.8epss 0.28

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2023-21689CriFeb 14, 2023
    risk 0.66cvss 9.8epss 0.27

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2022-24497CriApr 15, 2022
    risk 0.66cvss 9.8epss 0.35

    Windows Network File System Remote Code Execution Vulnerability

  • CVE-2022-24491CriApr 15, 2022
    risk 0.66cvss 9.8epss 0.33

    Windows Network File System Remote Code Execution Vulnerability

  • CVE-2021-24074CriFeb 25, 2021
    risk 0.66cvss 9.8epss 0.26

    Windows TCP/IP Remote Code Execution Vulnerability

  • CVE-2021-1647HigKEVJan 12, 2021
    risk 0.66cvss 7.8epss 0.39

    Microsoft Defender Remote Code Execution Vulnerability

  • CVE-2020-16009HigKEVNov 3, 2020
    risk 0.66cvss 8.8epss 0.49

    Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-1464HigKEVAug 17, 2020
    risk 0.66cvss 7.8epss 0.41

    A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features…

  • CVE-2020-0683HigKEVFeb 11, 2020
    risk 0.66cvss 7.8epss 0.08

    An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.

  • CVE-2019-1372CriOct 10, 2019
    risk 0.66cvss 10.0epss 0.19

    An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to…

  • CVE-2019-1132HigKEVJul 15, 2019
    risk 0.66cvss 7.8epss 0.10

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

  • CVE-2019-0863HigKEVMay 16, 2019
    risk 0.66cvss 7.8epss 0.05

    An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.

  • CVE-2019-0725CriMay 16, 2019
    risk 0.66cvss 9.8epss 0.26

    A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

  • CVE-2019-0697CriApr 9, 2019
    risk 0.66cvss 9.8epss 0.33

    A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726.

  • CVE-2018-8421CriSep 13, 2018
    risk 0.66cvss 9.8epss 0.29

    A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2,…

  • CVE-2018-8373HigKEVAug 15, 2018
    risk 0.66cvss 7.5epss 0.62

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is…

  • CVE-2018-8302CriAug 15, 2018
    risk 0.66cvss 9.8epss 0.26

    A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.

  • CVE-2018-8273CriAug 15, 2018
    risk 0.66cvss 9.8epss 0.29

    A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.

  • CVE-2018-12571CriJul 5, 2018
    risk 0.66cvss 9.8epss 0.30

    uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or…

  • CVE-2017-8686CriSep 13, 2017
    risk 0.66cvss 9.8epss 0.28

    The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows…

  • CVE-2017-8589CriJul 11, 2017
    risk 0.66cvss 9.8epss 0.26

    Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in…

  • CVE-2016-3227CriJun 16, 2016
    risk 0.66cvss 9.8epss 0.25

    Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability."

  • CVE-2016-3213HigJun 16, 2016
    risk 0.66cvss 8.8epss 0.67

    The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 9 through 11 has an…

  • CVE-2016-0003CriJan 13, 2016
    risk 0.66cvss 9.6epss 0.38

    Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Microsoft Edge Memory Corruption Vulnerability."

  • CVE-2015-2387HigKEVJul 14, 2015
    risk 0.66cvss 7.8epss 0.35

    ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges…

  • CVE-2012-1891CriJul 10, 2012
    risk 0.66cvss 9.8epss 0.29

    Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO…

  • CVE-2010-4398HigKEVDec 6, 2010
    risk 0.66cvss 7.8epss 0.09

    Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the…

  • CVE-2009-2512CriNov 11, 2009
    risk 0.66cvss 9.8epss 0.31

    The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, aka "Web Services…

  • CVE-2004-0210HigKEVAug 6, 2004
    risk 0.66cvss 7.8epss 0.07

    The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.

  • CVE-2002-0367HigKEVJun 25, 2002
    risk 0.66cvss 7.8epss 0.05

    smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.

  • CVE-2026-69502CriAug 21, 2026
    risk 0.65cvss 10.0epss 0.01

    Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-69836CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.02

    Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69555CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.00

    Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-65816CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.01

    Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-65801CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.01

    Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-65770CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.01

    Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.

  • CVE-2026-65667CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.01

    Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-63508CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.01

    Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-56162CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.01

    Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-58630CriJul 24, 2026
    risk 0.65cvss 10.0epss 0.00

    Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62825CriJul 24, 2026
    risk 0.65cvss 10.0epss 0.01

    Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-58275CriJul 24, 2026
    risk 0.65cvss 10.0epss 0.01

    Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-45480CriJun 19, 2026
    risk 0.65cvss 10.0epss 0.01

    Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-48567CriJun 4, 2026
    risk 0.65cvss 10.0epss 0.01

    Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-47280CriMay 22, 2026
    risk 0.65cvss 10.0epss 0.00

    Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-42901CriMay 22, 2026
    risk 0.65cvss 10.0epss 0.00

    Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

Page 7 of 314