58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.478 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2001-0340 | HIGH 7.5 | microsoft exchange_server An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed a | 6.4% | — |
| CVE-2018-0789 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". | 6.4% | — |
| CVE-2006-4066 | LOW 2.6 | microsoft windows_xp The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico file | 6.4% | — |
| CVE-2021-38659 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 6.4% | — |
| CVE-2021-38658 | HIGH 7.8 | microsoft office Microsoft Office Graphics Remote Code Execution Vulnerability | 6.4% | — |
| CVE-2021-38654 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 6.4% | — |
| CVE-2021-38653 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 6.4% | — |
| CVE-2012-1872 | MED 6.1 | microsoft internet_explorer Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability." | 6.4% | — |
| CVE-2013-0013 | MED 5.8 | microsoft windows_7 The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to c | 6.4% | — |
| CVE-2018-8579 | MED 6.5 | microsoft office An information disclosure vulnerability exists when attaching files to Outlook messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office. This CVE ID is unique from CVE-2018-8558. | 6.3% | — |
| CVE-2024-43502 | HIGH 7.1 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 6.3% | — |
| CVE-2020-1018 | HIGH 7.5 | microsoft dynamics_365_business_central An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could s | 6.3% | — |
| CVE-2020-36327 | HIGH 8.8 | bundler bundler Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a d | 6.3% | — |
| CVE-2021-24066 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Remote Code Execution Vulnerability | 6.3% | — |
| CVE-2022-30160 | HIGH 7.8 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 6.3% | — |
| CVE-2020-0882 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2 | 6.3% | — |
| CVE-2020-0880 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2 | 6.3% | — |
| CVE-2009-0243 | HIGH 7.2 | microsoft windows_2000 Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media, (3) connecting a USB device, and (4) c | 6.3% | — |
| CVE-1999-0582 | MED 5.0 | microsoft windows_2000 A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. | 6.3% | — |
| CVE-2017-11939 | MED 6.5 | microsoft office Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permissions, aka "Microsoft Office Information Disclosure Vulnerability". | 6.3% | — |
| CVE-2018-8422 | MED 6.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CV | 6.3% | — |
| CVE-2020-1113 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. An | 6.3% | — |
| CVE-2016-3220 | HIGH 7.8 | microsoft windows_10 atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges | 6.3% | — |
| CVE-2000-1218 | CRIT 9.8 | microsoft windows_2000 The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison | 6.3% | — |
| CVE-2023-35644 | HIGH 7.8 | microsoft windows_10_1809 Windows Sysmain Service Elevation of Privilege Vulnerability | 6.3% | — |