IT
56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2006-6578 HIGH 7.5 microsoft internet_information_services Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demonstrated u 7.0%
CVE-2001-1450 LOW 2.6 microsoft internet_explorer Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./". 7.0%
CVE-2001-0807 LOW 2.6 microsoft internet_explorer Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file. 7.0%
CVE-2024-38052 HIGH 7.8 microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability 7.0%
CVE-2020-0690 CRIT 9.8 microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. 7.0%
CVE-2019-0815 HIGH 7.5 microsoft asp.net_core A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. 7.0%
CVE-1999-0511 CRIT 9.1 microsoft windows_2000 IP forwarding is enabled on a machine which is not a router or firewall. 7.0%
CVE-1999-0967 HIGH 10.0 microsoft internet_explorer Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol. 7.0%
CVE-2026-42980 HIGH 7.8 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. 6.9%
CVE-2003-0503 HIGH 7.5 microsoft windows_2000 Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument. 6.9%
CVE-2020-1092 HIGH 7.5 microsoft internet_explorer A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who su 6.9%
CVE-2025-21204 HIGH 7.8 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. 6.9%
CVE-1999-0993 HIGH 7.5 microsoft exchange_server Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed. 6.9%
CVE-2016-0039 MED 6.1 microsoft sharepoint_foundation Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability." 6.9%
CVE-2006-3351 MED 5.4 microsoft windows_2003_server Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL and a 6.9%
CVE-2006-5884 HIGH 7.5 microsoft ie Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilities than C 6.9%
CVE-2018-8595 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve 6.9%
CVE-2019-1361 MED 5.5 microsoft windows_7 An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'. 6.9%
CVE-1999-1055 HIGH 7.5 microsoft excel Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability." 6.9%
CVE-2024-30034 MED 5.5 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability 6.9%
CVE-2021-21120 HIGH 8.8 google chrome Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. 6.9%
CVE-2005-1792 MED 5.0 microsoft windows_xp Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can be cleared from the RPC cache. 6.9%
CVE-2020-1284 MED 6.5 microsoft windows_10 A denial of service vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Denial of Service Vulnerability'. 6.9%
CVE-2016-0075 MED 5.5 microsoft windows_10 The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, ak 6.9%
CVE-2015-1636 LOW 3.5 microsoft sharepoint_foundation Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 Gold and SP1 and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS 6.9%