IT
58.650 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.478 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2002-0242 HIGH 7.5 microsoft internet_explorer Cross-site scripting vulnerability in Internet Explorer 6 earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, whose output from the remote server is not properly cleansed. 11.4% —
CVE-2026-21249 LOW 3.3 microsoft windows_10_1607 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally. 11.4% —
CVE-2014-6318 MED 4.3 microsoft windows_7 The audit logon feature in Remote Desktop Protocol (RDP) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly log unauthorized 11.4% —
CVE-2024-26160 MED 5.5 microsoft windows_11_22h2 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability 11.4% —
CVE-2002-2100 MED 5.0 microsoft outlook Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content. 11.4% —
CVE-2001-0723 MED 6.4 microsoft internet_explorer Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability." 11.4% —
CVE-2001-0643 MED 5.0 microsoft internet_explorer Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type. 11.4% —
CVE-2019-1102 HIGH 8.8 microsoft windows_10 A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. 11.3% —
CVE-2019-1159 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, 11.3% —
CVE-2007-1512 HIGH 10.0 microsoft visual_studio_.net Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to hav 11.3% —
CVE-2018-16793 HIGH 8.6 microsoft exchange_server Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page. 11.3% —
CVE-2008-1368 MED 4.3 microsoft internet_explorer CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded CRLF (%0D%0A) before the FTP command, which causes the commands to be inserted into an a 11.3% —
CVE-2008-3173 MED 6.8 microsoft internet_explorer Microsoft Internet Explorer allows web sites to set cookies for domains that have a public suffix with more than one dot character, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cookin 11.3% —
CVE-2022-35756 HIGH 7.8 microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability 11.3% —
CVE-2018-8391 HIGH 7.5 microsoft chakracore A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8354, CVE-2018-8456, CV 11.3% —
CVE-1999-1591 HIGH 7.5 microsoft internet_information_server Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated 11.3% —
CVE-2017-0007 MED 5.5 microsoft windows_10 Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidating associated signatures, aka "PowerShell Security Feature Bypass Vulnerability." 11.3% —
CVE-2002-0641 HIGH 7.5 microsoft msde Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query. 11.2% —
CVE-2020-1446 HIGH 8.8 microsoft 365_apps A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448. 11.2% —
CVE-2017-0161 HIGH 8.1 microsoft windows_10 The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vul 11.2% —
CVE-2008-5556 MED 4.3 microsoft internet_explorer The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injec 11.2% —
CVE-1999-1453 LOW 2.6 microsoft internet_explorer Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. 11.2% —
CVE-2001-0154 HIGH 7.5 microsoft internet_explorer HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly. 11.2% —
CVE-2005-4827 HIGH 7.5 canon network_camera_server_vb101 Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and c 11.2% —
CVE-2011-1713 MED 4.3 microsoft internet_explorer Microsoft msxml.dll, as used in Internet Explorer 8 on Windows 7, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function. NOTE: this might ov 11.2% —