IT
58.646 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.478 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2017-8748 HIGH 7.5 microsoft edge Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execut 11.8% —
CVE-2006-6266 MED 6.8 microsoft teredo Teredo clients, when following item 6 of RFC4380 section 5.2.3, start direct IPv6 connectivity tests (aka ping tests) in response to packets from non-Teredo source addresses, which might allow remote attackers to induce Teredo clients to send packets to third 11.8% —
CVE-2018-8468 MED 4.7 microsoft windows_10 An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, W 11.8% —
CVE-2011-2600 HIGH 7.1 microsoft windows_xp The GPU support functionality in Windows XP does not properly restrict rendering time, which allows remote attackers to cause a denial of service (system crash) via vectors involving WebGL and (1) shader programs or (2) complex 3D geometry, as demonstrated by 11.8% —
CVE-2022-29799 MED 5.5 microsoft windows_defender_for_endpoint A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispat 11.8% —
CVE-2022-29104 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 11.8% —
CVE-2023-41772 HIGH 7.8 microsoft windows_10_1809 Win32k Elevation of Privilege Vulnerability 11.8% —
CVE-2004-1173 HIGH 7.5 microsoft internet_explorer Internet Explorer 6 allows remote attackers to bypass the popup blocker via the document object model (DOM) methods in the DHTML Dynamic HTML (DHTML) Editing Component (DEC) and Javascript that calls showModalDialog. 11.7% —
CVE-2015-2516 MED 4.3 microsoft windows_10 Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to cause a denial of service (data loss) 11.7% —
CVE-2002-1769 HIGH 7.5 microsoft site_server Microsoft Site Server 3.0 prior to SP4 installs a default user, LDAP_Anonymous, with a default password of LdapPassword_1, which allows remote attackers the "Log on locally" privilege. 11.7% —
CVE-2002-0696 HIGH 7.5 microsoft visual_foxpro Microsoft Visual FoxPro 6.0 does not register its associated files with Internet Explorer, which allows remote attackers to execute Visual FoxPro applications without warning via HTML that references specially-crafted filenames. 11.7% —
CVE-1999-1397 HIGH 7.5 microsoft index_server Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed. 11.7% —
CVE-2018-0949 MED 6.5 microsoft internet_explorer A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UNC resources, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet 11.7% —
CVE-2000-0256 HIGH 7.5 microsoft frontpage Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability. 11.7% —
CVE-2014-2819 MED 6.8 microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability." 11.7% —
CVE-2013-5042 MED 4.3 microsoft asp.net_signalr Cross-site scripting (XSS) vulnerability in Microsoft ASP.NET SignalR 1.1.x before 1.1.4 and 2.0.x before 2.0.1, and Visual Studio Team Foundation Server 2013, allows remote attackers to inject arbitrary web script or HTML via crafted Forever Frame transport p 11.7% —
CVE-2023-23383 HIGH 8.2 microsoft azure_service_fabric Service Fabric Explorer Spoofing Vulnerability 11.7% —
CVE-2015-6164 MED 6.8 microsoft internet_explorer Microsoft Internet Explorer 9 through 11 improperly implements a cross-site scripting (XSS) protection mechanism, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, aka "Internet Explorer XSS Filter Bypass Vulnerability." 11.7% —
CVE-2020-1409 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. 11.7% —
CVE-2020-0967 HIGH 8.8 microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0966. 11.7% —
CVE-2020-0966 HIGH 8.8 microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0967. 11.7% —
CVE-2018-0919 LOW 3.3 microsoft office Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enter 11.7% —
CVE-1999-1520 MED 5.0 microsoft site_server A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information. 11.7% —
CVE-2019-1257 HIGH 8.8 microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1295, CVE-201 11.7% —
CVE-2018-8177 HIGH 7.5 microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-09 11.7% —