Vendor CVEs
Microsoft
All CVEs
15,658 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-41104 | Cri | 0.65 | 10.0 | 0.01 | May 22, 2026 | Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-40412 | Cri | 0.65 | 10.0 | 0.01 | May 22, 2026 | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-23652 | Cri | 0.65 | 10.0 | 0.01 | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42822 | Cri | 0.65 | 10.0 | 0.00 | May 18, 2026 | Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-42826 | Cri | 0.65 | 10.0 | 0.01 | May 7, 2026 | Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-35431 | Cri | 0.65 | 10.0 | 0.01 | Apr 23, 2026 | Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-33819 | Cri | 0.65 | 10.0 | 0.01 | Apr 23, 2026 | Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-32186 | Cri | 0.65 | 10.0 | 0.01 | Apr 3, 2026 | Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-33107 | Cri | 0.65 | 10.0 | 0.01 | Apr 3, 2026 | Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-33105 | Cri | 0.65 | 10.0 | 0.01 | Apr 3, 2026 | Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-32213 | Cri | 0.65 | 10.0 | 0.01 | Apr 3, 2026 | Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-32169 | Cri | 0.65 | 10.0 | 0.01 | Mar 19, 2026 | Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-65041 | Cri | 0.65 | 10.0 | 0.01 | Dec 18, 2025 | Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-65037 | Cri | 0.65 | 10.0 | 0.01 | Dec 18, 2025 | Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-49752 | Cri | 0.65 | 10.0 | 0.01 | Nov 20, 2025 | Azure Bastion Elevation of Privilege Vulnerability | ||
| CVE-2025-59503 | Cri | 0.65 | 10.0 | 0.01 | Oct 23, 2025 | Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-55241 | Cri | 0.65 | 10.0 | 0.02 | Sep 4, 2025 | Azure Entra ID Elevation of Privilege Vulnerability | ||
| CVE-2025-54914 | Cri | 0.65 | 10.0 | 0.02 | Sep 4, 2025 | Azure Networking Elevation of Privilege Vulnerability | ||
| CVE-2025-53767 | Cri | 0.65 | 10.0 | 0.01 | Aug 7, 2025 | Azure OpenAI Elevation of Privilege Vulnerability | ||
| CVE-2025-47981 | Cri | 0.65 | 9.8 | 0.32 | Jul 8, 2025 | Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-30397 | Hig | 0.65 | 7.5 | 0.27 | KEV | May 13, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | |
| CVE-2025-29972 | Cri | 0.65 | 9.9 | 0.03 | May 8, 2025 | Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2025-29813 | Cri | 0.65 | 10.0 | 0.02 | May 8, 2025 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-24989 | Hig | 0.65 | 8.2 | 0.02 | KEV | Feb 19, 2025 | An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been… | |
| CVE-2024-43602 | Cri | 0.65 | 9.9 | 0.02 | Nov 12, 2024 | Azure CycleCloud Remote Code Execution Vulnerability | ||
| CVE-2024-43491 | Cri | 0.65 | 9.8 | 0.12 | Sep 10, 2024 | Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated… | ||
| CVE-2024-21334 | Cri | 0.65 | 9.8 | 0.20 | Mar 12, 2024 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | ||
| CVE-2023-36397 | Cri | 0.65 | 9.8 | 0.18 | Nov 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-44487 | Hig | 0.65 | 7.5 | 1.00 | KEV | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| CVE-2023-36802 | Hig | 0.65 | 7.8 | 0.26 | KEV | Sep 12, 2023 | Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | |
| CVE-2023-0755 | Cri | 0.65 | 9.8 | 0.12 | Feb 23, 2023 | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code. | ||
| CVE-2023-21692 | Cri | 0.65 | 9.8 | 0.21 | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | ||
| CVE-2022-37968 | Cri | 0.65 | 10.0 | 0.03 | Oct 11, 2022 | Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster.… | ||
| CVE-2022-37969 | Hig | 0.65 | 7.8 | 0.28 | KEV | Sep 13, 2022 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2022-26925 | Hig | 0.65 | 8.1 | 0.11 | KEV | May 10, 2022 | Windows LSA Spoofing Vulnerability | |
| CVE-2021-43890 | Hig | 0.65 | 7.1 | 0.10 | KEV | Dec 15, 2021 | We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as… | |
| CVE-2021-42313 | Cri | 0.65 | 10.0 | 0.04 | Dec 15, 2021 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2021-42311 | Cri | 0.65 | 10.0 | 0.04 | Dec 15, 2021 | Microsoft Defender for IoT Remote Code Execution Vulnerability | ||
| CVE-2021-42292 | Hig | 0.65 | 7.8 | 0.43 | KEV | Nov 10, 2021 | Microsoft Excel Security Feature Bypass Vulnerability | |
| CVE-2021-26432 | Cri | 0.65 | 9.8 | 0.11 | Aug 12, 2021 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | ||
| CVE-2021-34458 | Cri | 0.65 | 9.9 | 0.03 | Jul 16, 2021 | Windows Kernel Remote Code Execution Vulnerability | ||
| CVE-2021-33742 | Hig | 0.65 | 7.5 | 0.59 | KEV | Jun 8, 2021 | Windows MSHTML Platform Remote Code Execution Vulnerability | |
| CVE-2021-26897 | Cri | 0.65 | 9.8 | 0.12 | Mar 11, 2021 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2021-26877 | Cri | 0.65 | 9.8 | 0.17 | Mar 11, 2021 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2021-26867 | Cri | 0.65 | 9.9 | 0.03 | Mar 11, 2021 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2021-24094 | Cri | 0.65 | 9.8 | 0.22 | Feb 25, 2021 | Windows TCP/IP Remote Code Execution Vulnerability | ||
| CVE-2021-24078 | Cri | 0.65 | 9.8 | 0.11 | Feb 25, 2021 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2020-16952 | Hig | 0.65 | 8.6 | 0.71 | Oct 16, 2020 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application… | ||
| CVE-2020-1595 | Cri | 0.65 | 9.9 | 0.02 | Sep 11, 2020 | A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the… | ||
| CVE-2020-1467 | Cri | 0.65 | 10.0 | 0.04 | Aug 17, 2020 | An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would first have to log… |
- risk 0.65cvss 10.0epss 0.01
Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.
- risk 0.65cvss 10.0epss 0.01
Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 10.0epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 10.0epss 0.00
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
- risk 0.65cvss 10.0epss 0.01
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
- risk 0.65cvss 10.0epss 0.01
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 10.0epss 0.01
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.01
Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 10.0epss 0.01
Azure Bastion Elevation of Privilege Vulnerability
- risk 0.65cvss 10.0epss 0.01
Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.02
Azure Entra ID Elevation of Privilege Vulnerability
- risk 0.65cvss 10.0epss 0.02
Azure Networking Elevation of Privilege Vulnerability
- risk 0.65cvss 10.0epss 0.01
Azure OpenAI Elevation of Privilege Vulnerability
- risk 0.65cvss 9.8epss 0.32
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 7.5epss 0.27
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 9.9epss 0.03
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.
- risk 0.65cvss 10.0epss 0.02
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
- risk 0.65cvss 8.2epss 0.02
An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been…
- risk 0.65cvss 9.9epss 0.02
Azure CycleCloud Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.12
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated…
- risk 0.65cvss 9.8epss 0.20
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.18
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.65cvss 7.5epss 1.00
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- risk 0.65cvss 7.8epss 0.26
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
- risk 0.65cvss 9.8epss 0.12
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
- risk 0.65cvss 9.8epss 0.21
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- risk 0.65cvss 10.0epss 0.03
Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster.…
- risk 0.65cvss 7.8epss 0.28
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.65cvss 8.1epss 0.11
Windows LSA Spoofing Vulnerability
- risk 0.65cvss 7.1epss 0.10
We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as…
- risk 0.65cvss 10.0epss 0.04
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.65cvss 10.0epss 0.04
Microsoft Defender for IoT Remote Code Execution Vulnerability
- risk 0.65cvss 7.8epss 0.43
Microsoft Excel Security Feature Bypass Vulnerability
- risk 0.65cvss 9.8epss 0.11
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
- risk 0.65cvss 9.9epss 0.03
Windows Kernel Remote Code Execution Vulnerability
- risk 0.65cvss 7.5epss 0.59
Windows MSHTML Platform Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.12
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.17
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.65cvss 9.9epss 0.03
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.22
Windows TCP/IP Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.11
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.65cvss 8.6epss 0.71
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application…
- risk 0.65cvss 9.9epss 0.02
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the…
- risk 0.65cvss 10.0epss 0.04
An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would first have to log…
Page 8 of 314