IT
56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2010-0808 LOW 2.6 microsoft internet_explorer Microsoft Internet Explorer 6 and 7 on Windows XP and Vista does not prevent script from simulating user interaction with the AutoComplete feature, which allows remote attackers to obtain sensitive form information via a crafted web site, aka "AutoComplete Inf 9.5%
CVE-2000-0202 HIGH 7.5 microsoft data_engine Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select statement in an SQL query. 9.5%
CVE-2025-50165 CRIT 9.8 microsoft windows_11_24h2 Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. 9.5%
CVE-2015-6044 MED 6.8 microsoft internet_explorer Microsoft Internet Explorer 8 allows remote attackers to gain privileges via a crafted web site, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Internet Explorer Elevation of Privilege Vulnerability." 9.5%
CVE-2017-11767 CRIT 9.8 microsoft chakracore ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". 9.5%
CVE-2000-0768 LOW 2.6 microsoft ie A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the "Frame Domain Verification" vulnerability. 9.5%
CVE-2002-2311 MED 6.4 microsoft internet_explorer Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was r 9.5%
CVE-2024-30087 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 9.5%
CVE-2019-1225 HIGH 7.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the system. To exploit this vul 9.5%
CVE-2017-8585 HIGH 7.5 microsoft .net_framework Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability. 9.5%
CVE-2017-11884 HIGH 7.8 microsoft excel Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-118 9.5%
CVE-2010-2119 MED 4.3 microsoft internet_explorer Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid nntp:// URIs. 9.5%
CVE-2015-2544 MED 4.3 microsoft exchange_server Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, aka "Exchange Spoofing Vulnera 9.5%
CVE-2015-2543 MED 4.3 microsoft exchange_server Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, aka "Exchange Spoofing Vulnerability." 9.5%
CVE-2000-0746 HIGH 7.5 microsoft frontpage Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the cl 9.5%
CVE-2013-1299 MED 5.8 microsoft modern_mail Microsoft Windows Modern Mail allows remote attackers to spoof link targets via a crafted HTML e-mail message. 9.5%
CVE-2021-21157 HIGH 8.8 fedoraproject fedora Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. 9.5%
CVE-2020-1067 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an 9.5%
CVE-2015-6170 MED 6.8 microsoft edge Microsoft Edge allows remote attackers to gain privileges via a crafted web site, aka "Microsoft Browser Elevation of Privilege Vulnerability." 9.4%
CVE-2007-2593 HIGH 7.5 microsoft terminal_server The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demo 9.4%
CVE-2006-4465 HIGH 10.0 microsoft terminal_server Microsoft Terminal Server, when running an application session with the "Start program at logon" and "Override settings from user profile and Client Connection Manager wizard" options, allows local users to execute arbitrary code by forcing an Explorer error. 9.4%
CVE-2015-1639 MED 4.3 microsoft office Cross-site scripting (XSS) vulnerability in Microsoft Office for Mac 2011 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Outlook App for Mac XSS Vulnerability." 9.4%
CVE-2022-24542 HIGH 7.8 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 9.4%
CVE-2009-0072 MED 4.3 microsoft internet_explorer Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application crash) via an onload=screen[""] attribute value in a BODY element. 9.4%
CVE-2007-2885 MED 4.3 microsoft visual_database_tools_database_designer The NotSafe function in the MSVDTDatabaseDesigner7 ActiveX control in VDT70.DLL in Microsoft Visual Database Tools (MSVDT) Database Designer 7.0 allows remote attackers to cause a denial of service (Internet Explorer 6 crash) via a long argument. 9.4%