56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-0981 | MED 5.3 | microsoft internet_explorer An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Ex | 6.7% | — |
| CVE-2021-38656 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 6.7% | — |
| CVE-2007-3954 | MED 4.3 | microsoft internet_explorer Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with SeaMonkey installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metachara | 6.7% | — |
| CVE-2018-1040 | MED 5.3 | microsoft windows_10 A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Windows Code Integrity Module Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 200 | 6.7% | — |
| CVE-2017-8531 | MED 6.5 | microsoft office Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 Service Pack 3, and Microsoft Office 2010 Service Pack 2 | 6.7% | — |
| CVE-2017-0170 | MED 6.5 | microsoft windows_10 Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability due to the | 6.7% | — |
| CVE-2018-0800 | MED 5.3 | microsoft chakracore Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is | 6.7% | — |
| CVE-2018-8175 | MED 6.5 | microsoft windows_10 An denial of service vulnerability exists when Windows NT WEBDAV Minirdr attempts to query a WEBDAV directory, aka "WEBDAV Denial of Service Vulnerability." This affects Windows 10 Servers, Windows 10. | 6.7% | — |
| CVE-2024-26170 | HIGH 7.8 | microsoft windows_10_21h2 Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability | 6.6% | — |
| CVE-2024-25110 | CRIT 9.8 | microsoft azure_uamqp The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. U | 6.6% | — |
| CVE-2019-1013 | MED 4.7 | microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are | 6.6% | — |
| CVE-2020-17141 | HIGH 8.4 | microsoft exchange_server Microsoft Exchange Remote Code Execution Vulnerability | 6.6% | — |
| CVE-2010-1689 | MED 6.4 | microsoft exchange_server The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and ear | 6.6% | — |
| CVE-2021-43893 | HIGH 7.5 | microsoft windows_10 Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability | 6.6% | — |
| CVE-2016-3341 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Transaction Manager in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Windows Transaction Manager Eleva | 6.6% | — |
| CVE-2016-3270 | HIGH 7.8 | microsoft windows_10 The Graphics component in the kernel in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via | 6.6% | — |
| CVE-2019-1374 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'. | 6.6% | — |
| CVE-2021-28312 | LOW 3.3 | microsoft windows_10 Windows NTFS Denial of Service Vulnerability | 6.6% | — |
| CVE-2021-34467 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 6.6% | — |
| CVE-2023-28227 | HIGH 7.5 | microsoft windows_10_1507 Windows Bluetooth Driver Remote Code Execution Vulnerability | 6.6% | — |
| CVE-2001-0345 | MED 5.0 | microsoft windows_2000 Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions. | 6.6% | — |
| CVE-2017-0045 | MED 5.5 | microsoft windows_7 Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Fo | 6.6% | — |
| CVE-2020-0853 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'. | 6.6% | — |
| CVE-2010-1690 | MED 6.4 | microsoft exchange_server The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and ear | 6.6% | — |
| CVE-2022-21894 | MED 4.4 | microsoft windows_10 Secure Boot Security Feature Bypass Vulnerability | 6.6% | — |