VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2025-29823HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-29822HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2025-29820HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-29812HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

  • CVE-2025-29811HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.

  • CVE-2025-29801HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-29800HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-29791HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-27752HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-27750HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2025-27749HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-27748HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-27747HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-27746HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-27745HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-27744HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27743HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27741HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-27739HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27733HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-27731HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27730HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27729HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Windows Shell allows an unauthorized attacker to execute code locally.

  • CVE-2025-27728HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27727HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27490HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27489HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27483HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

  • CVE-2025-27476HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-27467HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26688HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26679HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26675HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26674HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

  • CVE-2025-26666HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.

  • CVE-2025-26648HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26642HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-26639HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24074HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24073HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24062HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24060HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24058HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2025-21204HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.07

    Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

  • CVE-2025-29795HigMar 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

  • CVE-2025-26630HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.

  • CVE-2025-26629HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-24995HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-24083HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-24082HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

Page 74 of 314