58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.478 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-1657 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | 12.9% | — |
| CVE-2024-26218 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 12.9% | — |
| CVE-2024-43491 | CRIT 9.8 | microsoft windows_10_1507 Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these pre | 12.9% | — |
| CVE-2013-3880 | LOW 3.5 | microsoft windows_8 The App Container feature in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to bypass intended access restrictions and obtain sensitive information from a different container via a Trojan horse appli | 12.9% | — |
| CVE-2006-2056 | MED 5.0 | microsoft internet_explorer Argument injection vulnerability in Internet Explorer 6 for Windows XP SP2 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launchin | 12.9% | — |
| CVE-2018-8461 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-8447. | 12.9% | — |
| CVE-2018-8447 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is uni | 12.9% | — |
| CVE-2006-7029 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a frameset with only one frame that calls resizeTo with certain arguments. NOTE: this issue might be related to CVE-2006-3637. | 12.9% | — |
| CVE-2019-1245 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1244, CVE-2019-1251. | 12.9% | — |
| CVE-2007-3576 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 6 executes web script from URIs of arbitrary scheme names ending with the "script" character sequence, using the (1) vbscript: handler for scheme names with 7 through 9 characters, and the (2) javascript: handler for scheme names wi | 12.9% | — |
| CVE-2003-1505 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in a div element whose scrollbar-base-color is modified by a CSS style, which is then moved. | 12.9% | — |
| CVE-2002-2073 | MED 4.3 | microsoft site_server Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) ctr parameter in Default.asp and (2) the query string to formslogin.asp. | 12.9% | — |
| CVE-2007-5145 | MED 4.3 | microsoft windows_xp Multiple buffer overflows in system DLL files in Microsoft Windows XP, as used by Microsoft Windows Explorer (explorer.exe) 6.00.2900.2180, Don Ho Notepad++, unspecified Adobe Macromedia applications, and other programs, allow user-assisted remote attackers to | 12.8% | — |
| CVE-2005-1214 | MED 5.1 | microsoft windows_2000 Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page. | 12.8% | — |
| CVE-2000-0156 | MED 5.1 | microsoft internet_explorer Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability. | 12.8% | — |
| CVE-1999-0281 | MED 5.0 | microsoft internet_information_server Denial of service in IIS using long URLs. | 12.8% | — |
| CVE-2009-5092 | MED 4.3 | microsoft fast_esp Cross-site scripting (XSS) vulnerability in the management interface in Microsoft FAST ESP 5.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 12.8% | — |
| CVE-2016-3376 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl | 12.8% | — |
| CVE-2015-6061 | MED 4.3 | microsoft lync Cross-site scripting (XSS) vulnerability in Microsoft Skype for Business 2016, Lync 2010 and 2013 SP1, Lync 2010 Attendee, and Lync Room System allows remote attackers to inject arbitrary web script or HTML via an instant-message session, aka "Server Input Val | 12.8% | — |
| CVE-2014-6354 | HIGH 7.5 | microsoft internet_explorer Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11 allows remote attackers to execute arbitrary code. | 12.8% | — |
| CVE-2000-0885 | HIGH 7.5 | microsoft systems_management_server Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol P | 12.8% | — |
| CVE-1999-0332 | HIGH 7.5 | microsoft netmeeting Buffer overflow in NetMeeting allows denial of service and remote command execution. | 12.8% | — |
| CVE-2017-0158 | HIGH 7.5 | microsoft windows_10 An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption Vulnerabi | 12.8% | — |
| CVE-2018-8509 | HIGH 7.5 | microsoft edge A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8473. | 12.8% | — |
| CVE-2018-8491 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-8460. | 12.8% | — |