VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2026-41104CriMay 22, 2026
    risk 0.65cvss 10.0epss 0.01

    Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-40412CriMay 22, 2026
    risk 0.65cvss 10.0epss 0.01

    Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

  • CVE-2026-23652CriMay 22, 2026
    risk 0.65cvss 10.0epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42822CriMay 18, 2026
    risk 0.65cvss 10.0epss 0.00

    Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-42826CriMay 7, 2026
    risk 0.65cvss 10.0epss 0.01

    Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-35431CriApr 23, 2026
    risk 0.65cvss 10.0epss 0.01

    Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-33819CriApr 23, 2026
    risk 0.65cvss 10.0epss 0.01

    Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

  • CVE-2026-32186CriApr 3, 2026
    risk 0.65cvss 10.0epss 0.01

    Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-33107CriApr 3, 2026
    risk 0.65cvss 10.0epss 0.01

    Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-33105CriApr 3, 2026
    risk 0.65cvss 10.0epss 0.01

    Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-32213CriApr 3, 2026
    risk 0.65cvss 10.0epss 0.01

    Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-32169CriMar 19, 2026
    risk 0.65cvss 10.0epss 0.01

    Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-65041CriDec 18, 2025
    risk 0.65cvss 10.0epss 0.01

    Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-65037CriDec 18, 2025
    risk 0.65cvss 10.0epss 0.01

    Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

  • CVE-2025-49752CriNov 20, 2025
    risk 0.65cvss 10.0epss 0.01

    Azure Bastion Elevation of Privilege Vulnerability

  • CVE-2025-59503CriOct 23, 2025
    risk 0.65cvss 10.0epss 0.01

    Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-55241CriSep 4, 2025
    risk 0.65cvss 10.0epss 0.02

    Azure Entra ID Elevation of Privilege Vulnerability

  • CVE-2025-54914CriSep 4, 2025
    risk 0.65cvss 10.0epss 0.02

    Azure Networking Elevation of Privilege Vulnerability

  • CVE-2025-53767CriAug 7, 2025
    risk 0.65cvss 10.0epss 0.01

    Azure OpenAI Elevation of Privilege Vulnerability

  • CVE-2025-47981CriJul 8, 2025
    risk 0.65cvss 9.8epss 0.32

    Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.

  • CVE-2025-30397HigKEVMay 13, 2025
    risk 0.65cvss 7.5epss 0.27

    Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

  • CVE-2025-29972CriMay 8, 2025
    risk 0.65cvss 9.9epss 0.03

    Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.

  • CVE-2025-29813CriMay 8, 2025
    risk 0.65cvss 10.0epss 0.02

    Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-24989HigKEVFeb 19, 2025
    risk 0.65cvss 8.2epss 0.02

    An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been…

  • CVE-2024-43602CriNov 12, 2024
    risk 0.65cvss 9.9epss 0.02

    Azure CycleCloud Remote Code Execution Vulnerability

  • CVE-2024-43491CriSep 10, 2024
    risk 0.65cvss 9.8epss 0.12

    Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated…

  • CVE-2024-21334CriMar 12, 2024
    risk 0.65cvss 9.8epss 0.20

    Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

  • CVE-2023-36397CriNov 14, 2023
    risk 0.65cvss 9.8epss 0.18

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

  • CVE-2023-44487HigKEVOct 10, 2023
    risk 0.65cvss 7.5epss 1.00

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2023-36802HigKEVSep 12, 2023
    risk 0.65cvss 7.8epss 0.26

    Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

  • CVE-2023-0755CriFeb 23, 2023
    risk 0.65cvss 9.8epss 0.12

    The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

  • CVE-2023-21692CriFeb 14, 2023
    risk 0.65cvss 9.8epss 0.21

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2022-37968CriOct 11, 2022
    risk 0.65cvss 10.0epss 0.03

    Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster.…

  • CVE-2022-37969HigKEVSep 13, 2022
    risk 0.65cvss 7.8epss 0.28

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2022-26925HigKEVMay 10, 2022
    risk 0.65cvss 8.1epss 0.11

    Windows LSA Spoofing Vulnerability

  • CVE-2021-43890HigKEVDec 15, 2021
    risk 0.65cvss 7.1epss 0.10

    We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as…

  • CVE-2021-42313CriDec 15, 2021
    risk 0.65cvss 10.0epss 0.04

    Microsoft Defender for IoT Remote Code Execution Vulnerability

  • CVE-2021-42311CriDec 15, 2021
    risk 0.65cvss 10.0epss 0.04

    Microsoft Defender for IoT Remote Code Execution Vulnerability

  • CVE-2021-42292HigKEVNov 10, 2021
    risk 0.65cvss 7.8epss 0.43

    Microsoft Excel Security Feature Bypass Vulnerability

  • CVE-2021-26432CriAug 12, 2021
    risk 0.65cvss 9.8epss 0.11

    Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

  • CVE-2021-34458CriJul 16, 2021
    risk 0.65cvss 9.9epss 0.03

    Windows Kernel Remote Code Execution Vulnerability

  • CVE-2021-33742HigKEVJun 8, 2021
    risk 0.65cvss 7.5epss 0.59

    Windows MSHTML Platform Remote Code Execution Vulnerability

  • CVE-2021-26897CriMar 11, 2021
    risk 0.65cvss 9.8epss 0.12

    Windows DNS Server Remote Code Execution Vulnerability

  • CVE-2021-26877CriMar 11, 2021
    risk 0.65cvss 9.8epss 0.17

    Windows DNS Server Remote Code Execution Vulnerability

  • CVE-2021-26867CriMar 11, 2021
    risk 0.65cvss 9.9epss 0.03

    Windows Hyper-V Remote Code Execution Vulnerability

  • CVE-2021-24094CriFeb 25, 2021
    risk 0.65cvss 9.8epss 0.22

    Windows TCP/IP Remote Code Execution Vulnerability

  • CVE-2021-24078CriFeb 25, 2021
    risk 0.65cvss 9.8epss 0.11

    Windows DNS Server Remote Code Execution Vulnerability

  • CVE-2020-16952HigOct 16, 2020
    risk 0.65cvss 8.6epss 0.71

    A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application…

  • CVE-2020-1595CriSep 11, 2020
    risk 0.65cvss 9.9epss 0.02

    A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the…

  • CVE-2020-1467CriAug 17, 2020
    risk 0.65cvss 10.0epss 0.04

    An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would first have to log…

Page 8 of 314