Microsoft
microsoft
14,964 CVEs • 1,050 products
Products (1,050)
Click to collapseToggle
Products (1,050)
Click to collapse
CVEs (14,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Windows 8.1 Windows Server 2012May 13, 2026 Apr 12, 2017 N/A· v4 5.4 MEDIUM· v3 5.2 MEDIUM· v2 An information disclosure vulnerability exists when Windows Hyper-V running on a Windows 8.1, Windows Server 2012. or Windows Server 2012 R2 host operating system fails to properly validate input from an authenticated us...Show more |
1Microsoft 3Windows 8.1 Windows Server 2008Windows Server 2012May 13, 2026 Apr 12, 2017 N/A· v4 5.8 MEDIUM· v3 6.3 MEDIUM· v2 An information disclosure vulnerability exists when the Windows Hyper-V Network Switch running on a Windows 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, or Windows Server 2012 R2 host operating...Show more |
1Microsoft 5Windows 10 Windows 8.1Windows Rt 8.1+2 moreMay 13, 2026 Apr 12, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Windows kernel improperly handles objects in memory. An attacker who suc...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreMay 13, 2026 Apr 12, 2017 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially craft...Show more |
1Microsoft 4Windows 10 Windows 8.1Windows Rt 8.1+1 moreMay 13, 2026 Apr 12, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Win...Show more |
1Microsoft 2Windows 10 Windows Server 2016May 13, 2026 Apr 12, 2017 N/A· v4 4.4 MEDIUM· v3 3.5 LOW· v2 A denial of service vulnerability exists in Windows 10 1607 and Windows Server 2016 Active Directory when an authenticated attacker sends malicious search queries, aka "Active Directory Denial of Service Vulnerability." |
1Microsoft 5Windows 10 Windows 8.1Windows Server 2008+2 moreMay 13, 2026 Apr 12, 2017 N/A· v4 7.6 HIGH· v3 7.4 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code...Show more |
1Microsoft 4Windows 10 Windows 8.1Windows Server 2012+1 moreMay 13, 2026 Apr 12, 2017 N/A· v4 7.6 HIGH· v3 7.4 HIGH· v2 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from an a...Show more |
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability." |
1Microsoft 3Windows 10 Windows Server 2012Windows Server 2016May 13, 2026 Apr 12, 2017 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A security feature bypass vulnerability exists in Windows 10 1607, Windows Server 2012 R2, and Windows 2016 when ADFS incorrectly treats requests coming from Extranet clients as Intranet requests, aka "ADFS Security Feat...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreMay 13, 2026 Apr 12, 2017 N/A· v4 7.5 HIGH· v3 7.6 HIGH· v2 An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scri...Show more |
1Microsoft 7Windows 10 Windows 7Windows 8.1+4 moreMay 13, 2026 Apr 12, 2017 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 An elevation of privilege vulnerability exists in Windows 7, Windows 8.1, Windows RT 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 when the Microsoft Graphi...Show more |
1Microsoft 3Windows 7 Windows Server 2008Windows VistaMay 13, 2026 Apr 12, 2017 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 The Graphics component in the kernel in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Graphics Elevation...Show more |
Microsoft Excel 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted...Show more |
A remote code execution vulnerability in Microsoft Edge exists in the way that the Scripting Engine renders when handling objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreMay 13, 2026 Apr 12, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain informatio...Show more |
1Microsoft 1Internet Information Services Apr 21, 2026 Mar 27, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long heade...Show more |
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by...Show more |
1Microsoft 1Internet Explorer May 13, 2026 Mar 17, 2017 N/A· v4 4.4 MEDIUM· v3 5.8 MEDIUM· v2 Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a craft...Show more |
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an...Show more |