58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.478 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-53143 | HIGH 8.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | 8.1% | — |
| CVE-2006-5395 | HIGH 7.5 | microsoft class_package_export_tool Buffer overflow in Microsoft Class Package Export Tool (aka clspack.exe) allows context-dependent attackers to execute arbitrary code via a long string. NOTE: the provenance of this information is unknown; the details are obtained from third party information | 8.1% | — |
| CVE-2021-21125 | HIGH 8.1 | google chrome Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. | 8.1% | — |
| CVE-2015-0009 | LOW 3.3 | microsoft windows_7 The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow | 8.1% | — |
| CVE-2019-1001 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1004, CVE-2019-1056, CVE-2019-1059. | 8.1% | — |
| CVE-2020-1223 | HIGH 8.8 | microsoft word A remote code execution vulnerability exists when Microsoft Word for Android fails to properly handle certain files.To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted URL file.The update addresses the vulnerabil | 8.0% | — |
| CVE-2017-11813 | HIGH 7.5 | microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute arbitrary code in the context of the current user, due to how Internet Explorer handles objects i | 8.0% | — |
| CVE-2025-32711 | CRIT 9.3 | microsoft 365_copilot Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 8.0% | — |
| CVE-2019-1471 | HIGH 8.2 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. | 8.0% | — |
| CVE-2024-21437 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 8.0% | — |
| CVE-2018-0924 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative U | 8.0% | — |
| CVE-2025-53766 | CRIT 9.8 | microsoft 365_copilot Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 8.0% | — |
| CVE-2018-16794 | HIGH 8.6 | microsoft active_directory_federation_services Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls. | 8.0% | — |
| CVE-2006-1511 | MED 5.1 | microsoft .net_framework Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name. | 8.0% | — |
| CVE-2020-1215 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260 | 8.0% | — |
| CVE-2020-1214 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260 | 8.0% | — |
| CVE-2017-8592 | MED 6.5 | microsoft edge Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows RT 8.1, and Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a security feature bypass vulnerability when they | 8.0% | — |
| CVE-2008-1888 | MED 4.3 | microsoft sharepoint_server Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor. | 8.0% | — |
| CVE-2019-0918 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0884, CVE-2019-0911. | 8.0% | — |
| CVE-2019-0780 | HIGH 7.5 | microsoft edge A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'. | 8.0% | — |
| CVE-2018-8398 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve | 8.0% | — |
| CVE-2018-8394 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve | 8.0% | — |
| CVE-2017-11871 | HIGH 7.5 | microsoft chakracore ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vul | 8.0% | — |
| CVE-2017-11866 | HIGH 7.5 | microsoft chakracore ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka " | 8.0% | — |
| CVE-2017-11836 | HIGH 7.5 | microsoft chakracore ChakraCore, and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to take control of an affected system, due to how the scripting engine handles objects in memory, aka " | 8.0% | — |