Vulnerabilities > Microsoft > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-03-12 CVE-2024-21431 Unspecified vulnerability in Microsoft products
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
local
low complexity
microsoft
6.7
2024-02-13 CVE-2024-20679 Unspecified vulnerability in Microsoft Azure Stack HUB
Azure Stack Hub Spoofing Vulnerability
network
low complexity
microsoft
6.5
2024-01-09 CVE-2024-20692 Exposure of Resource to Wrong Sphere vulnerability in Microsoft products
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
network
low complexity
microsoft CWE-668
5.7
2024-01-09 CVE-2024-21320 Unspecified vulnerability in Microsoft products
Windows Themes Spoofing Vulnerability
network
low complexity
microsoft
6.5
2023-12-18 CVE-2023-48795 Improper Validation of Integrity Check Value vulnerability in multiple products
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack.
5.9
2023-12-12 CVE-2023-36020 Cross-site Scripting vulnerability in Microsoft Dynamics 365
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
network
low complexity
microsoft CWE-79
5.4
2023-12-05 CVE-2023-49282 Unspecified vulnerability in Microsoft Graph 1.16.0/2.0.0
msgraph-sdk-php is the Microsoft Graph Library for PHP.
network
low complexity
microsoft
5.3
2023-12-05 CVE-2023-49283 Unspecified vulnerability in Microsoft Graph
microsoft-graph-core the Microsoft Graph Library for PHP.
network
low complexity
microsoft
5.3
2023-11-28 CVE-2023-24023 Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS.
high complexity
bluetooth microsoft
6.8
2023-11-20 CVE-2023-36013 Exposure of Resource to Wrong Sphere vulnerability in Microsoft Powershell
PowerShell Information Disclosure Vulnerability
network
low complexity
microsoft CWE-668
6.5