VYPR

Vendor CVEs

Microsoft

All CVEs

15,658 total · sorted by risk
  • CVE-2020-1380HigKEVAug 17, 2020
    risk 0.65cvss 7.8epss 0.24

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker…

  • CVE-2020-6102CriJul 20, 2020
    risk 0.65cvss 9.9epss 0.03

    An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.19000. An attacker can provide a a specially crafted shader file to trigger this vulnerability, resulting in code execution. This vulnerability…

  • CVE-2020-1054HigKEVMay 21, 2020
    risk 0.65cvss 7.0epss 0.54

    An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs;…

  • CVE-2020-0901CriMay 21, 2020
    risk 0.65cvss 9.8epss 0.04

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is…

  • CVE-2019-1384CriNov 12, 2019
    risk 0.65cvss 9.9epss 0.06

    A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass…

  • CVE-2019-1373CriNov 12, 2019
    risk 0.65cvss 9.8epss 0.18

    A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.

  • CVE-2019-1365CriOct 10, 2019
    risk 0.65cvss 9.9epss 0.04

    An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the…

  • CVE-2019-1306CriSep 11, 2019
    risk 0.65cvss 9.8epss 0.17

    A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.

  • CVE-2019-1182CriAug 14, 2019
    risk 0.65cvss 9.8epss 0.17

    A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and…

  • CVE-2019-1072CriJul 15, 2019
    risk 0.65cvss 9.8epss 0.12

    A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.

  • CVE-2019-0586CriJan 8, 2019
    risk 0.65cvss 9.8epss 0.15

    A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.

  • CVE-2018-8626CriDec 12, 2018
    risk 0.65cvss 9.8epss 0.21

    A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10,…

  • CVE-2018-8540CriDec 12, 2018
    risk 0.65cvss 9.8epss 0.22

    A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework…

  • CVE-2018-8529CriNov 15, 2018
    risk 0.65cvss 9.8epss 0.13

    A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team.

  • CVE-2018-8327CriJul 11, 2018
    risk 0.65cvss 9.8epss 0.21

    A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension.

  • CVE-2018-8154CriMay 9, 2018
    risk 0.65cvss 9.8epss 0.24

    A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151.

  • CVE-2018-0986HigApr 4, 2018
    risk 0.65cvss 8.8epss 0.63

    A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender,…

  • CVE-2017-0028CriJul 17, 2017
    risk 0.65cvss 9.8epss 0.19

    A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully…

  • CVE-2017-0089HigMar 17, 2017
    risk 0.65cvss 8.8epss 0.57

    Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in…

  • CVE-2016-3222HigJun 16, 2016
    risk 0.65cvss 8.8epss 0.57

    Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability."

  • CVE-2016-0132CriMar 9, 2016
    risk 0.65cvss 9.8epss 0.22

    Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents, which allows remote attackers to spoof signatures via a modified document, aka ".NET XML Validation Security Feature Bypass."

  • CVE-2008-3465CriDec 10, 2008
    risk 0.65cvss 9.8epss 0.14

    Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed…

  • CVE-2006-3730HigJul 21, 2006
    risk 0.65cvss 8.8epss 0.64

    Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory…

  • CVE-2026-69851CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.00

    Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-68789CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-68782CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-63509CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-65791CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62893CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.03

    Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62878CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62815CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

  • CVE-2026-59124CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.02

    Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62873CriAug 7, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62830CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-59115CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-50515CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

  • CVE-2026-50481CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-54120CriJul 24, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

  • CVE-2026-54118CriJul 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-54117CriJul 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-48584CriJun 19, 2026
    risk 0.64cvss 9.9epss 0.01

    Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-54130CriJun 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-47647CriJun 18, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-47643CriJun 9, 2026
    risk 0.64cvss 9.8epss 0.01

    External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.

  • CVE-2026-47291CriJun 9, 2026
    risk 0.64cvss 9.8epss 0.23

    Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

  • CVE-2026-45657CriJun 9, 2026
    risk 0.64cvss 9.8epss 0.15

    Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

  • CVE-2026-44815CriJun 9, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-40411CriMay 22, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

  • CVE-2026-42898CriMay 12, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

  • CVE-2026-42823CriMay 12, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

Page 9 of 314