VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2025-48815HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-48806HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.

  • CVE-2025-48805HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.

  • CVE-2025-48799HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-48000HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47996HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47994HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.03

    Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-47993HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47991HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47985HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47982HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47976HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47973HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-47971HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-47159HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

  • CVE-2025-49741HigJul 1, 2025
    risk 0.51cvss 7.4epss 0.04

    No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-47968HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47962HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47955HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2025-47176HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.

  • CVE-2025-47174HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-47173HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-47170HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-47169HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-47168HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-33075HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2025-32718HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally.

  • CVE-2025-32716HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-32714HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2025-32713HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-32712HigJun 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-32707HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-32705HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

  • CVE-2025-32702HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.

  • CVE-2025-30393HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-30388HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.04

    Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

  • CVE-2025-30385HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-30383HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-30382HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.02

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

  • CVE-2025-30381HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-30379HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-30376HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-30375HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-29979HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-29978HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

  • CVE-2025-29977HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-29976HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.

  • CVE-2025-29975HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

  • CVE-2025-29970HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24063HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

Page 73 of 314