58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.478 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-28227 | HIGH 7.5 | microsoft windows_10_1507 Windows Bluetooth Driver Remote Code Execution Vulnerability | 6.6% | — |
| CVE-2001-0345 | MED 5.0 | microsoft windows_2000 Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions. | 6.6% | — |
| CVE-2017-0045 | MED 5.5 | microsoft windows_7 Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Fo | 6.6% | — |
| CVE-2020-0853 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'. | 6.6% | — |
| CVE-2020-0951 | MED 6.7 | microsoft powershell <p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be | 6.6% | — |
| CVE-2010-1690 | MED 6.4 | microsoft exchange_server The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and ear | 6.6% | — |
| CVE-2022-21894 | MED 4.4 | microsoft windows_10 Secure Boot Security Feature Bypass Vulnerability | 6.6% | — |
| CVE-2020-1597 | HIGH 7.5 | fedoraproject fedora A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited re | 6.6% | — |
| CVE-2015-2527 | HIGH 7.2 | microsoft windows_10 The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 does not properly constrain impersonation levels, which allows loca | 6.6% | — |
| CVE-2017-11761 | MED 5.3 | microsoft exchange_server Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability" | 6.6% | — |
| CVE-2019-1035 | HIGH 7.8 | microsoft office A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context o | 6.6% | — |
| CVE-2018-8409 | HIGH 7.5 | microsoft .net_core A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1. | 6.6% | — |
| CVE-2005-1981 | LOW 2.1 | microsoft windows_2000 Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message. | 6.6% | — |
| CVE-2019-0930 | MED 6.5 | microsoft internet_explorer An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'. | 6.6% | — |
| CVE-2019-0746 | MED 6.5 | microsoft chakracore An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'. | 6.6% | — |
| CVE-2019-0614 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0774. | 6.6% | — |
| CVE-2023-35631 | HIGH 7.8 | microsoft windows_11_21h2 Win32k Elevation of Privilege Vulnerability | 6.5% | — |
| CVE-2023-35632 | HIGH 7.8 | microsoft windows_10_1507 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 6.5% | — |
| CVE-2021-43217 | HIGH 8.1 | microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability | 6.5% | — |
| CVE-2017-8623 | MED 6.8 | microsoft windows_10 Windows Hyper-V in Windows 10 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability". | 6.5% | — |
| CVE-2022-24474 | HIGH 7.8 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 6.5% | — |
| CVE-2021-21128 | HIGH 8.8 | google chrome Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 6.5% | — |
| CVE-2006-5758 | HIGH 7.2 | microsoft windows_2000 The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, wh | 6.5% | — |
| CVE-2024-43504 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 6.5% | — |
| CVE-2002-0699 | MED 5.0 | microsoft windows_2000 Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system vi | 6.5% | — |