IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.478 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-28227 HIGH 7.5 microsoft windows_10_1507 Windows Bluetooth Driver Remote Code Execution Vulnerability 6.6% —
CVE-2001-0345 MED 5.0 microsoft windows_2000 Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions. 6.6% —
CVE-2017-0045 MED 5.5 microsoft windows_7 Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Fo 6.6% —
CVE-2020-0853 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'. 6.6% —
CVE-2020-0951 MED 6.7 microsoft powershell <p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be 6.6% —
CVE-2010-1690 MED 6.4 microsoft exchange_server The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and ear 6.6% —
CVE-2022-21894 MED 4.4 microsoft windows_10 Secure Boot Security Feature Bypass Vulnerability 6.6% —
CVE-2020-1597 HIGH 7.5 fedoraproject fedora A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited re 6.6% —
CVE-2015-2527 HIGH 7.2 microsoft windows_10 The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 does not properly constrain impersonation levels, which allows loca 6.6% —
CVE-2017-11761 MED 5.3 microsoft exchange_server Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability" 6.6% —
CVE-2019-1035 HIGH 7.8 microsoft office A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context o 6.6% —
CVE-2018-8409 HIGH 7.5 microsoft .net_core A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1. 6.6% —
CVE-2005-1981 LOW 2.1 microsoft windows_2000 Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message. 6.6% —
CVE-2019-0930 MED 6.5 microsoft internet_explorer An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'. 6.6% —
CVE-2019-0746 MED 6.5 microsoft chakracore An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'. 6.6% —
CVE-2019-0614 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0774. 6.6% —
CVE-2023-35631 HIGH 7.8 microsoft windows_11_21h2 Win32k Elevation of Privilege Vulnerability 6.5% —
CVE-2023-35632 HIGH 7.8 microsoft windows_10_1507 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 6.5% —
CVE-2021-43217 HIGH 8.1 microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability 6.5% —
CVE-2017-8623 MED 6.8 microsoft windows_10 Windows Hyper-V in Windows 10 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability". 6.5% —
CVE-2022-24474 HIGH 7.8 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 6.5% —
CVE-2021-21128 HIGH 8.8 google chrome Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. 6.5% —
CVE-2006-5758 HIGH 7.2 microsoft windows_2000 The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, wh 6.5% —
CVE-2024-43504 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 6.5% —
CVE-2002-0699 MED 5.0 microsoft windows_2000 Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system vi 6.5% —