56.561 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-6138 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 8 through 11 mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Internet Explorer XSS Filter Bypass Vulnerability." | 12.1% | — |
| CVE-2015-2398 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability." | 12.1% | — |
| CVE-2019-1244 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1245, CVE-2019-1251. | 12.1% | — |
| CVE-2001-0665 | HIGH 7.5 | microsoft ie Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP | 12.1% | — |
| CVE-2022-29104 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 12.1% | — |
| CVE-2011-1991 | HIGH 9.3 | microsoft windows_2003_server Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in t | 12.1% | — |
| CVE-2019-0639 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0680, CVE-2019-0769, CVE-2019-077 | 12.0% | — |
| CVE-2004-2179 | MED 5.0 | microsoft frontpage asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values. | 12.0% | — |
| CVE-2002-0444 | HIGH 7.5 | microsoft windows_2000_terminal_services Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses | 12.0% | — |
| CVE-1999-0909 | HIGH 7.5 | microsoft terminal_server Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability. | 12.0% | — |
| CVE-2015-3097 | MED 5.0 | adobe air Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK & Compiler before 18.0.0.144 on 64-bit Windows 7 systems do not properly select a random memory addres | 12.0% | — |
| CVE-2016-7250 | HIGH 8.8 | microsoft sql_server Microsoft SQL Server 2014 SP1, 2014 SP2, and 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability." | 12.0% | — |
| CVE-2002-1262 | HIGH 7.5 | microsoft internet_explorer Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files. | 12.0% | — |
| CVE-1999-0777 | HIGH 7.5 | microsoft commercial_internet_system IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions. | 12.0% | — |
| CVE-2020-17083 | MED 5.5 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 12.0% | — |
| CVE-2002-1340 | MED 5.0 | microsoft office_web_components The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting an exception. | 12.0% | — |
| CVE-2002-1339 | MED 5.0 | microsoft office_web_components The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files. | 12.0% | — |
| CVE-2024-43532 | HIGH 8.8 | microsoft windows_10_1507 Remote Registry Service Elevation of Privilege Vulnerability | 12.0% | — |
| CVE-2020-0852 | HIGH 7.8 | microsoft office A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0855, CVE-20 | 12.0% | — |
| CVE-2021-43883 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 12.0% | — |
| CVE-2008-1200 | HIGH 9.3 | microsoft access Unspecified vulnerability in Microsoft Access allows remote user-assisted attackers to execute arbitrary code via a crafted .MDB file, possibly related to Jet Engine (msjet40.dll). NOTE: this is probably a different issue than CVE-2007-6026. | 12.0% | — |
| CVE-2007-0913 | HIGH 9.3 | microsoft powerpoint Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G. NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006- | 12.0% | — |
| CVE-2019-1441 | HIGH 8.8 | microsoft windows_7 A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'. | 12.0% | — |
| CVE-1999-0989 | HIGH 7.5 | microsoft ie Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol. | 11.9% | — |
| CVE-2018-0772 | HIGH 7.5 | microsoft chakracore Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an att | 11.9% | — |