56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-3333 | HIGH 7.8 | microsoft windows_10 The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local user | 6.8% | — |
| CVE-2016-3332 | HIGH 7.8 | microsoft windows_10 The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local user | 6.8% | — |
| CVE-2016-0026 | HIGH 7.8 | microsoft windows_10 The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local user | 6.8% | — |
| CVE-2008-1084 | HIGH 7.2 | microsoft windows_2000 Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation. NOTE: it was late | 6.8% | — |
| CVE-2018-1007 | MED 5.3 | microsoft office An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-0950. | 6.7% | — |
| CVE-1999-0581 | HIGH 10.0 | microsoft windows_nt The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. | 6.7% | — |
| CVE-1999-0898 | HIGH 7.2 | microsoft windows_nt Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request. | 6.7% | — |
| CVE-2019-1212 | CRIT 9.8 | microsoft windows_10 A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. An attacker who successfully exploited the vulnerability could cause the DHCP server service to stop responding. To exploit the vulnerability | 6.7% | — |
| CVE-2019-0835 | MED 6.5 | microsoft internet_explorer An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory, aka 'Microsoft Scripting Engine Information Disclosure Vulnerability'. | 6.7% | — |
| CVE-2018-17612 | HIGH 7.5 | microsoft windows_10 Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which allows remote attackers | 6.7% | — |
| CVE-2020-1375 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'. | 6.7% | — |
| CVE-2021-31974 | HIGH 7.5 | microsoft windows_10 Server for NFS Denial of Service Vulnerability | 6.7% | — |
| CVE-2019-1116 | MED 6.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2 | 6.7% | — |
| CVE-2019-1101 | MED 6.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2 | 6.7% | — |
| CVE-2019-1100 | MED 6.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1098, CVE-2 | 6.7% | — |
| CVE-2019-1098 | MED 6.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1099, CVE-2 | 6.7% | — |
| CVE-2019-1095 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1098, CVE-2019-1099, CVE-2 | 6.7% | — |
| CVE-2019-1094 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1095, CVE-2019-1098, CVE-2019-1099, CVE-2 | 6.7% | — |
| CVE-2023-36394 | HIGH 7.0 | microsoft windows_10_1507 Windows Search Service Elevation of Privilege Vulnerability | 6.7% | — |
| CVE-2023-20569 | MED 4.7 | amd epyc_72f3_firmware A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. | 6.7% | — |
| CVE-2022-24474 | HIGH 7.8 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 6.7% | — |
| CVE-2021-26896 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability | 6.7% | — |
| CVE-2001-0145 | HIGH 7.5 | microsoft outlook Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field. | 6.7% | — |
| CVE-1999-0285 | HIGH 10.0 | microsoft windows_nt Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. | 6.7% | — |
| CVE-2019-0982 | HIGH 7.5 | microsoft asp.net_core A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. | 6.7% | — |