58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.478 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2011-0029 | HIGH 7.4 | microsoft remote_desktop_connection_client Untrusted search path vulnerability in the client in Microsoft Remote Desktop Connection 5.2, 6.0, 6.1, and 7.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rdp f | 7.2% | — |
| CVE-2017-8532 | MED 6.5 | microsoft office Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Graphics Uniscribe Infor | 7.1% | — |
| CVE-1999-0994 | MED 5.0 | microsoft windows_nt Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords. | 7.1% | — |
| CVE-2019-0833 | MED 6.5 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka 'Microsoft Edge Information Disclosure Vulnerability'. | 7.1% | — |
| CVE-2016-3292 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows remote attackers to bypass a sandbox protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability." | 7.1% | — |
| CVE-2006-1591 | MED 5.1 | microsoft windows_2000 Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to execute arbitrary code via crafted embedded image data in a .hlp file. | 7.1% | — |
| CVE-2015-2429 | HIGH 9.3 | microsoft windows_7 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow attackers to bypass an application sandbox protection mechanism and perform unspecified r | 7.1% | — |
| CVE-2020-1577 | HIGH 7.8 | microsoft windows_10 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways | 7.1% | — |
| CVE-2020-1230 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1260 | 7.1% | — |
| CVE-2019-1104 | HIGH 7.5 | microsoft edge A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'. | 7.1% | — |
| CVE-2018-8596 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve | 7.1% | — |
| CVE-2014-6336 | LOW 3.5 | microsoft exchange_server Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the origin of e-mail messages via unspecified ve | 7.1% | — |
| CVE-1999-0993 | HIGH 7.5 | microsoft exchange_server Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed. | 7.1% | — |
| CVE-2019-1374 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'. | 7.1% | — |
| CVE-2017-0175 | MED 4.7 | microsoft windows_7 The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability th | 7.0% | — |
| CVE-2005-0904 | LOW 2.1 | microsoft windows_xp Remote Desktop in Windows XP SP1 does not verify the "Force shutdown from a remote system" setting, which allows remote attackers to shut down the system by executing TSShutdn.exe. | 7.0% | — |
| CVE-2004-2643 | LOW 3.7 | microsoft cabarc Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via "../" sequences in file names in a CAB archive. | 7.0% | — |
| CVE-2017-11848 | MED 4.3 | microsoft internet_explorer Internet Explorer in Microsoft Microsoft Windows 7 SP1, Windows Server 2008 SP2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to det | 7.0% | — |
| CVE-2017-0274 | MED 5.9 | microsoft windows_10 Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, an | 7.0% | — |
| CVE-2006-6578 | HIGH 7.5 | microsoft internet_information_services Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demonstrated u | 7.0% | — |
| CVE-2022-30157 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 7.0% | — |
| CVE-2017-0110 | MED 6.1 | microsoft exchange_server Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrary web script or HTML via a crafted email or chat client, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." | 7.0% | — |
| CVE-2021-26893 | CRIT 9.8 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 7.0% | — |
| CVE-2021-38665 | HIGH 7.4 | microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability | 7.0% | — |
| CVE-1999-1055 | HIGH 7.5 | microsoft excel Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability." | 7.0% | — |