58.646 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.478 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-8748 | HIGH 7.5 | microsoft edge Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execut | 11.8% | — |
| CVE-2006-6266 | MED 6.8 | microsoft teredo Teredo clients, when following item 6 of RFC4380 section 5.2.3, start direct IPv6 connectivity tests (aka ping tests) in response to packets from non-Teredo source addresses, which might allow remote attackers to induce Teredo clients to send packets to third | 11.8% | — |
| CVE-2018-8468 | MED 4.7 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, W | 11.8% | — |
| CVE-2011-2600 | HIGH 7.1 | microsoft windows_xp The GPU support functionality in Windows XP does not properly restrict rendering time, which allows remote attackers to cause a denial of service (system crash) via vectors involving WebGL and (1) shader programs or (2) complex 3D geometry, as demonstrated by | 11.8% | — |
| CVE-2022-29799 | MED 5.5 | microsoft windows_defender_for_endpoint A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispat | 11.8% | — |
| CVE-2022-29104 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 11.8% | — |
| CVE-2023-41772 | HIGH 7.8 | microsoft windows_10_1809 Win32k Elevation of Privilege Vulnerability | 11.8% | — |
| CVE-2004-1173 | HIGH 7.5 | microsoft internet_explorer Internet Explorer 6 allows remote attackers to bypass the popup blocker via the document object model (DOM) methods in the DHTML Dynamic HTML (DHTML) Editing Component (DEC) and Javascript that calls showModalDialog. | 11.7% | — |
| CVE-2015-2516 | MED 4.3 | microsoft windows_10 Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to cause a denial of service (data loss) | 11.7% | — |
| CVE-2002-1769 | HIGH 7.5 | microsoft site_server Microsoft Site Server 3.0 prior to SP4 installs a default user, LDAP_Anonymous, with a default password of LdapPassword_1, which allows remote attackers the "Log on locally" privilege. | 11.7% | — |
| CVE-2002-0696 | HIGH 7.5 | microsoft visual_foxpro Microsoft Visual FoxPro 6.0 does not register its associated files with Internet Explorer, which allows remote attackers to execute Visual FoxPro applications without warning via HTML that references specially-crafted filenames. | 11.7% | — |
| CVE-1999-1397 | HIGH 7.5 | microsoft index_server Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed. | 11.7% | — |
| CVE-2018-0949 | MED 6.5 | microsoft internet_explorer A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UNC resources, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet | 11.7% | — |
| CVE-2000-0256 | HIGH 7.5 | microsoft frontpage Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability. | 11.7% | — |
| CVE-2014-2819 | MED 6.8 | microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability." | 11.7% | — |
| CVE-2013-5042 | MED 4.3 | microsoft asp.net_signalr Cross-site scripting (XSS) vulnerability in Microsoft ASP.NET SignalR 1.1.x before 1.1.4 and 2.0.x before 2.0.1, and Visual Studio Team Foundation Server 2013, allows remote attackers to inject arbitrary web script or HTML via crafted Forever Frame transport p | 11.7% | — |
| CVE-2023-23383 | HIGH 8.2 | microsoft azure_service_fabric Service Fabric Explorer Spoofing Vulnerability | 11.7% | — |
| CVE-2015-6164 | MED 6.8 | microsoft internet_explorer Microsoft Internet Explorer 9 through 11 improperly implements a cross-site scripting (XSS) protection mechanism, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, aka "Internet Explorer XSS Filter Bypass Vulnerability." | 11.7% | — |
| CVE-2020-1409 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. | 11.7% | — |
| CVE-2020-0967 | HIGH 8.8 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0966. | 11.7% | — |
| CVE-2020-0966 | HIGH 8.8 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0967. | 11.7% | — |
| CVE-2018-0919 | LOW 3.3 | microsoft office Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enter | 11.7% | — |
| CVE-1999-1520 | MED 5.0 | microsoft site_server A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information. | 11.7% | — |
| CVE-2019-1257 | HIGH 8.8 | microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1295, CVE-201 | 11.7% | — |
| CVE-2018-8177 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-09 | 11.7% | — |