IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.478 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2001-0340 HIGH 7.5 microsoft exchange_server An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed a 6.4% —
CVE-2018-0789 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". 6.4% —
CVE-2006-4066 LOW 2.6 microsoft windows_xp The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico file 6.4% —
CVE-2021-38659 HIGH 7.8 microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability 6.4% —
CVE-2021-38658 HIGH 7.8 microsoft office Microsoft Office Graphics Remote Code Execution Vulnerability 6.4% —
CVE-2021-38654 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 6.4% —
CVE-2021-38653 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 6.4% —
CVE-2012-1872 MED 6.1 microsoft internet_explorer Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 9 allows remote attackers to inject arbitrary web script or HTML via crafted character sequences with EUC-JP encoding, aka "EUC-JP Character Encoding Vulnerability." 6.4% —
CVE-2013-0013 MED 5.8 microsoft windows_7 The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to c 6.4% —
CVE-2018-8579 MED 6.5 microsoft office An information disclosure vulnerability exists when attaching files to Outlook messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office. This CVE ID is unique from CVE-2018-8558. 6.3% —
CVE-2024-43502 HIGH 7.1 microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 6.3% —
CVE-2020-1018 HIGH 7.5 microsoft dynamics_365_business_central An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could s 6.3% —
CVE-2020-36327 HIGH 8.8 bundler bundler Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a d 6.3% —
CVE-2021-24066 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Remote Code Execution Vulnerability 6.3% —
CVE-2022-30160 HIGH 7.8 microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 6.3% —
CVE-2020-0882 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2 6.3% —
CVE-2020-0880 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2 6.3% —
CVE-2009-0243 HIGH 7.2 microsoft windows_2000 Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media, (3) connecting a USB device, and (4) c 6.3% —
CVE-1999-0582 MED 5.0 microsoft windows_2000 A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. 6.3% —
CVE-2017-11939 MED 6.5 microsoft office Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permissions, aka "Microsoft Office Information Disclosure Vulnerability". 6.3% —
CVE-2018-8422 MED 6.5 microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CV 6.3% —
CVE-2020-1113 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. An 6.3% —
CVE-2016-3220 HIGH 7.8 microsoft windows_10 atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges 6.3% —
CVE-2000-1218 CRIT 9.8 microsoft windows_2000 The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison 6.3% —
CVE-2023-35644 HIGH 7.8 microsoft windows_10_1809 Windows Sysmain Service Elevation of Privilege Vulnerability 6.3% —