58.586 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.478 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2005-0509 | MED 4.3 | microsoft .net_framework Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII c | 15.9% | — |
| CVE-2017-0060 | MED 5.5 | microsoft live_meeting The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive | 15.9% | — |
| CVE-2001-0336 | MED 5.0 | microsoft internet_information_server The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request. | 15.9% | — |
| CVE-2013-3159 | MED 4.3 | microsoft excel Microsoft Excel 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Excel Viewer; and Microsoft Office Compatibility Pack SP3 allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity refer | 15.9% | — |
| CVE-2015-6057 | MED 5.0 | microsoft edge Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." | 15.9% | — |
| CVE-2009-3267 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 6 through 6.0.2900.2180, and 7.0.6000.16711, allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828. | 15.9% | — |
| CVE-2024-38060 | HIGH 8.8 | microsoft windows_10_1507 Windows Imaging Component Remote Code Execution Vulnerability | 15.9% | — |
| CVE-2016-0055 | HIGH 7.8 | microsoft office Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." | 15.9% | — |
| CVE-2018-8628 | HIGH 7.8 | microsoft office A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Micro | 15.9% | — |
| CVE-2016-3267 | MED 5.3 | microsoft edge Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of unspecified files via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | 15.9% | — |
| CVE-2016-3377 | HIGH 7.5 | microsoft edge The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE | 15.9% | — |
| CVE-2015-2506 | HIGH 9.3 | microsoft windows_10 atmfd.dll in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to cause a d | 15.9% | — |
| CVE-2017-8619 | HIGH 7.5 | microsoft edge Microsoft Edge on Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way affected Microsoft scripting engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulner | 15.9% | — |
| CVE-2002-1762 | MED 5.0 | microsoft baseline_security_analyzer Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plaintext, which could allow remote attackers to obtain sensitive information about the system via malicious active co | 15.9% | — |
| CVE-2000-1079 | HIGH 7.5 | microsoft windows_2000 Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram. | 15.9% | — |
| CVE-2002-2077 | MED 5.0 | microsoft windows_2000 The DCOM client in Windows 2000 before SP3 does not properly clear memory before sending an "alter context" request, which may allow remote attackers to obtain sensitive information by sniffing the session. | 15.9% | — |
| CVE-2018-8475 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Se | 15.9% | — |
| CVE-2008-4299 | MED 5.0 | microsoft internet_authentication_service_helper_com_component A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll allows remote attackers to cause a denial of service (browser crash) via a large integer value in the first argument to the PutProperty method. | 15.9% | — |
| CVE-2013-0015 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 6 through 9 does not properly perform auto-selection of the Shift JIS encoding, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site that triggers cross-domain scrolling events | 15.9% | — |
| CVE-2019-1333 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. | 15.9% | — |
| CVE-2007-3481 | MED 5.0 | microsoft internet_explorer Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the documen | 15.8% | — |
| CVE-2023-36019 | CRIT 9.6 | microsoft azure_logic_apps Microsoft Power Platform Connector Spoofing Vulnerability | 15.8% | — |
| CVE-2016-3326 | MED 5.3 | microsoft edge Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Browser Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3327. | 15.8% | — |
| CVE-2019-0571 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, | 15.8% | — |
| CVE-2008-3009 | HIGH 10.0 | microsoft windows_media_format_runtime Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote | 15.8% | — |