IT
56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-38051 HIGH 7.8 microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability 7.3%
CVE-2022-38050 HIGH 7.8 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 7.3%
CVE-2020-1493 MED 5.5 microsoft 365_apps An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users 7.3%
CVE-2005-1207 HIGH 7.2 microsoft windows_2003_server Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters. 7.3%
CVE-2020-1113 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. An 7.3%
CVE-2021-1645 MED 5.0 microsoft windows_10 Windows Docker Information Disclosure Vulnerability 7.3%
CVE-2018-8416 MED 6.5 microsoft asp.net_core A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1. 7.3%
CVE-2026-20959 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 7.2%
CVE-2017-11872 MED 6.5 microsoft edge Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to force the browser to send data that would otherwise be restricted to a destination website of the attacker's choice, due to how Microsoft Edge handles redirect req 7.2%
CVE-2017-0276 MED 5.9 microsoft windows_10 Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, an 7.2%
CVE-2017-0270 MED 5.9 microsoft windows_10 Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, an 7.2%
CVE-2017-0268 MED 5.9 microsoft windows_10 Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, an 7.2%
CVE-2023-36391 HIGH 7.8 microsoft windows_11_23h2 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability 7.2%
CVE-2019-1332 MED 6.1 microsoft power_bi_report_server A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'. 7.2%
CVE-2018-0741 MED 5.3 microsoft windows_7 The Color Management Module (Icm32.dll) in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Microsoft Color Management Information Disclosure Vulnerability". 7.2%
CVE-2016-3276 LOW 3.1 microsoft internet_explorer Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability." 7.2%
CVE-2023-35641 HIGH 8.8 microsoft windows_10_1507 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability 7.2%
CVE-2010-2567 HIGH 9.3 microsoft windows_server_2003 The RPC client implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly allocate memory during the parsing of responses, which allows remote RPC servers and man-in-the-middle attackers to execute arbitrary code via a malformed r 7.2%
CVE-2020-0824 HIGH 7.5 microsoft internet_explorer A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. 7.2%
CVE-1999-0766 HIGH 9.3 microsoft java_virtual_machine The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment. 7.2%
CVE-1999-0249 HIGH 7.2 microsoft windows_2000 Windows NT RSHSVC program allows remote users to execute arbitrary commands. 7.2%
CVE-1999-0994 MED 5.0 microsoft windows_nt Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords. 7.2%
CVE-2017-8726 MED 4.3 microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how affected Microsoft scripting engines handle objects in memory, aka "Microsoft Edg 7.2%
CVE-2017-8563 HIGH 8.1 microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Kerberos falling back to N 7.2%
CVE-2020-1260 HIGH 7.5 microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230 7.2%