Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2025-01-14 CVE-2025-21311 Unspecified vulnerability in Microsoft products
Windows NTLM V1 Elevation of Privilege Vulnerability
network
low complexity
microsoft
critical
9.8
2025-01-14 CVE-2025-21313 Unspecified vulnerability in Microsoft products
Windows Security Account Manager (SAM) Denial of Service Vulnerability
network
low complexity
microsoft
6.5
2025-01-14 CVE-2025-21315 Unspecified vulnerability in Microsoft products
Microsoft Brokering File System Elevation of Privilege Vulnerability
local
high complexity
microsoft
7.8
2025-01-14 CVE-2025-21326 Unspecified vulnerability in Microsoft Windows Server 2022 23H2 and Windows Server 2025
Internet Explorer Remote Code Execution Vulnerability
local
low complexity
microsoft
7.8
2025-01-14 CVE-2025-21332 Unspecified vulnerability in Microsoft products
MapUrlToZone Security Feature Bypass Vulnerability
network
low complexity
microsoft
8.8
2025-01-09 CVE-2025-21380 Unspecified vulnerability in Microsoft Azure Marketplace
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.
network
low complexity
microsoft
6.5
2025-01-09 CVE-2025-21385 Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview
A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.
network
low complexity
microsoft CWE-918
6.5
2024-12-12 CVE-2024-49071 Unspecified vulnerability in Microsoft Defender for Endpoint
Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network.
network
low complexity
microsoft
6.5
2024-12-12 CVE-2024-49147 Deserialization of Untrusted Data vulnerability in Microsoft Update Catalog
Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.
network
low complexity
microsoft CWE-502
critical
9.8
2024-12-12 CVE-2024-49057 Unspecified vulnerability in Microsoft Defender for Endpoint
Microsoft Defender for Endpoint on Android Spoofing Vulnerability
network
low complexity
microsoft
8.1