56.568 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26160 | MED 5.5 | microsoft windows_11_22h2 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | 11.4% | — |
| CVE-2002-2100 | MED 5.0 | microsoft outlook Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content. | 11.4% | — |
| CVE-2001-0723 | MED 6.4 | microsoft internet_explorer Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability." | 11.4% | — |
| CVE-2001-0643 | MED 5.0 | microsoft internet_explorer Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type. | 11.4% | — |
| CVE-2019-1102 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | 11.3% | — |
| CVE-2021-26432 | CRIT 9.8 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | 11.3% | — |
| CVE-2019-1159 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 11.3% | — |
| CVE-2007-1512 | HIGH 10.0 | microsoft visual_studio_.net Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to hav | 11.3% | — |
| CVE-2018-16793 | HIGH 8.6 | microsoft exchange_server Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page. | 11.3% | — |
| CVE-2023-20588 | MED 5.5 | amd athlon_gold_3150g_firmware A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. | 11.3% | — |
| CVE-2008-1368 | MED 4.3 | microsoft internet_explorer CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded CRLF (%0D%0A) before the FTP command, which causes the commands to be inserted into an a | 11.3% | — |
| CVE-2008-3173 | MED 6.8 | microsoft internet_explorer Microsoft Internet Explorer allows web sites to set cookies for domains that have a public suffix with more than one dot character, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cookin | 11.3% | — |
| CVE-2022-35756 | HIGH 7.8 | microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability | 11.3% | — |
| CVE-2020-1446 | HIGH 8.8 | microsoft 365_apps A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448. | 11.3% | — |
| CVE-1999-1591 | HIGH 7.5 | microsoft internet_information_server Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated | 11.3% | — |
| CVE-2017-0007 | MED 5.5 | microsoft windows_10 Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidating associated signatures, aka "PowerShell Security Feature Bypass Vulnerability." | 11.3% | — |
| CVE-2020-0979 | HIGH 8.8 | microsoft office_365_proplus A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0906. | 11.3% | — |
| CVE-2020-0906 | HIGH 8.8 | microsoft excel A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0979. | 11.3% | — |
| CVE-2020-1117 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install | 11.2% | — |
| CVE-2002-0641 | HIGH 7.5 | microsoft msde Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query. | 11.2% | — |
| CVE-2017-0161 | HIGH 8.1 | microsoft windows_10 The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vul | 11.2% | — |
| CVE-2008-5556 | MED 4.3 | microsoft internet_explorer The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injec | 11.2% | — |
| CVE-1999-1453 | LOW 2.6 | microsoft internet_explorer Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. | 11.2% | — |
| CVE-2001-0154 | HIGH 7.5 | microsoft internet_explorer HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly. | 11.2% | — |
| CVE-2026-40372 | CRIT 9.1 | microsoft asp.net_core Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. | 11.2% | — |