IT
56.568 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-26160 MED 5.5 microsoft windows_11_22h2 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability 11.4%
CVE-2002-2100 MED 5.0 microsoft outlook Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content. 11.4%
CVE-2001-0723 MED 6.4 microsoft internet_explorer Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability." 11.4%
CVE-2001-0643 MED 5.0 microsoft internet_explorer Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type. 11.4%
CVE-2019-1102 HIGH 8.8 microsoft windows_10 A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. 11.3%
CVE-2021-26432 CRIT 9.8 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability 11.3%
CVE-2019-1159 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, 11.3%
CVE-2007-1512 HIGH 10.0 microsoft visual_studio_.net Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to hav 11.3%
CVE-2018-16793 HIGH 8.6 microsoft exchange_server Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page. 11.3%
CVE-2023-20588 MED 5.5 amd athlon_gold_3150g_firmware A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.  11.3%
CVE-2008-1368 MED 4.3 microsoft internet_explorer CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded CRLF (%0D%0A) before the FTP command, which causes the commands to be inserted into an a 11.3%
CVE-2008-3173 MED 6.8 microsoft internet_explorer Microsoft Internet Explorer allows web sites to set cookies for domains that have a public suffix with more than one dot character, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cookin 11.3%
CVE-2022-35756 HIGH 7.8 microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability 11.3%
CVE-2020-1446 HIGH 8.8 microsoft 365_apps A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448. 11.3%
CVE-1999-1591 HIGH 7.5 microsoft internet_information_server Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated 11.3%
CVE-2017-0007 MED 5.5 microsoft windows_10 Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidating associated signatures, aka "PowerShell Security Feature Bypass Vulnerability." 11.3%
CVE-2020-0979 HIGH 8.8 microsoft office_365_proplus A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0906. 11.3%
CVE-2020-0906 HIGH 8.8 microsoft excel A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0979. 11.3%
CVE-2020-1117 HIGH 8.8 microsoft windows_10 A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install 11.2%
CVE-2002-0641 HIGH 7.5 microsoft msde Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query. 11.2%
CVE-2017-0161 HIGH 8.1 microsoft windows_10 The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vul 11.2%
CVE-2008-5556 MED 4.3 microsoft internet_explorer The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injec 11.2%
CVE-1999-1453 LOW 2.6 microsoft internet_explorer Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. 11.2%
CVE-2001-0154 HIGH 7.5 microsoft internet_explorer HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly. 11.2%
CVE-2026-40372 CRIT 9.1 microsoft asp.net_core Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. 11.2%