IT
56.561 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2015-6138 MED 4.3 microsoft internet_explorer Microsoft Internet Explorer 8 through 11 mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Internet Explorer XSS Filter Bypass Vulnerability." 12.1%
CVE-2015-2398 MED 4.3 microsoft internet_explorer Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the XSS filter via a crafted attribute of an element in an HTML document, aka "Internet Explorer XSS Filter Bypass Vulnerability." 12.1%
CVE-2019-1244 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1245, CVE-2019-1251. 12.1%
CVE-2001-0665 HIGH 7.5 microsoft ie Internet Explorer 6 and earlier allows remote attackers to cause certain HTTP requests to be automatically executed and appear to come from the user, which could allow attackers to gain privileges or execute operations within web-based services, aka the "HTTP 12.1%
CVE-2022-29104 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 12.1%
CVE-2011-1991 HIGH 9.3 microsoft windows_2003_server Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in t 12.1%
CVE-2019-0639 HIGH 7.5 microsoft internet_explorer A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0680, CVE-2019-0769, CVE-2019-077 12.0%
CVE-2004-2179 MED 5.0 microsoft frontpage asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values. 12.0%
CVE-2002-0444 HIGH 7.5 microsoft windows_2000_terminal_services Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses 12.0%
CVE-1999-0909 HIGH 7.5 microsoft terminal_server Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability. 12.0%
CVE-2015-3097 MED 5.0 adobe air Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe AIR SDK & Compiler before 18.0.0.144 on 64-bit Windows 7 systems do not properly select a random memory addres 12.0%
CVE-2016-7250 HIGH 8.8 microsoft sql_server Microsoft SQL Server 2014 SP1, 2014 SP2, and 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability." 12.0%
CVE-2002-1262 HIGH 7.5 microsoft internet_explorer Internet Explorer 5.5 and 6.0 does not perform complete security checks on external caching, which allows remote attackers to read arbitrary files. 12.0%
CVE-1999-0777 HIGH 7.5 microsoft commercial_internet_system IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions. 12.0%
CVE-2020-17083 MED 5.5 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 12.0%
CVE-2002-1340 MED 5.0 microsoft office_web_components The "ConnectionFile" property in the DataSourceControl component in Office Web Components (OWC) 10 allows remote attackers to determine the existence of local files by detecting an exception. 12.0%
CVE-2002-1339 MED 5.0 microsoft office_web_components The "XMLURL" property in the Spreadsheet component of Office Web Components (OWC) 10 follows redirections, which allows remote attackers to determine the existence of local files based on exceptions, or to read WorkSheet XML files. 12.0%
CVE-2024-43532 HIGH 8.8 microsoft windows_10_1507 Remote Registry Service Elevation of Privilege Vulnerability 12.0%
CVE-2020-0852 HIGH 7.8 microsoft office A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0855, CVE-20 12.0%
CVE-2021-43883 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 12.0%
CVE-2008-1200 HIGH 9.3 microsoft access Unspecified vulnerability in Microsoft Access allows remote user-assisted attackers to execute arbitrary code via a crafted .MDB file, possibly related to Jet Engine (msjet40.dll). NOTE: this is probably a different issue than CVE-2007-6026. 12.0%
CVE-2007-0913 HIGH 9.3 microsoft powerpoint Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G. NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006- 12.0%
CVE-2019-1441 HIGH 8.8 microsoft windows_7 A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'. 12.0%
CVE-1999-0989 HIGH 7.5 microsoft ie Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol. 11.9%
CVE-2018-0772 HIGH 7.5 microsoft chakracore Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an att 11.9%