58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.478 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-8234 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-0871. | 6.3% | — |
| CVE-2018-0871 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when Edge improperly marks files, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8234. | 6.3% | — |
| CVE-1999-0579 | HIGH 10.0 | microsoft windows_nt A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. | 6.2% | — |
| CVE-1999-0577 | HIGH 10.0 | microsoft windows_nt A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. | 6.2% | — |
| CVE-2022-22034 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 6.2% | — |
| CVE-2001-0147 | HIGH 10.0 | microsoft windows_2000 Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records. | 6.2% | — |
| CVE-2020-1062 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who su | 6.2% | — |
| CVE-2022-21849 | CRIT 9.8 | microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 6.2% | — |
| CVE-2018-1021 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8123. | 6.2% | — |
| CVE-2019-1356 | MED 6.5 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'. | 6.2% | — |
| CVE-2023-28288 | HIGH 8.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 6.2% | — |
| CVE-2018-0952 | HIGH 7.8 | microsoft visual_studio_2015 An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Micr | 6.2% | — |
| CVE-2017-8521 | HIGH 7.5 | microsoft edge Microsoft Edge in Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user when the Edge JavaScript scripting engine fails to handle objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID i | 6.2% | — |
| CVE-2017-8596 | HIGH 7.5 | microsoft edge Microsoft Edge in Microsoft Windows 10 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Edge, aka "Scr | 6.2% | — |
| CVE-2021-28324 | HIGH 7.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 6.2% | — |
| CVE-2019-0821 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0703, CVE-2019-0704. | 6.2% | — |
| CVE-2018-8598 | MED 4.7 | microsoft excel An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel. This CVE ID is | 6.2% | — |
| CVE-2000-0439 | LOW 2.6 | microsoft internet_explorer Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability. | 6.2% | — |
| CVE-2019-1209 | MED 6.5 | microsoft lync An information disclosure vulnerability exists in Lync 2013, aka 'Lync 2013 Information Disclosure Vulnerability'. | 6.2% | — |
| CVE-1999-0917 | MED 5.1 | microsoft internet_explorer The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files. | 6.2% | — |
| CVE-2006-5805 | MED 5.0 | microsoft ie Microsoft Internet Explorer 7 allows remote attackers to cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/invalidcert.htm with the target site as an argument, which displays the site's URL in the address bar | 6.2% | — |
| CVE-2024-38244 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming Service Driver Elevation of Privilege Vulnerability | 6.2% | — |
| CVE-2021-21121 | CRIT 9.6 | google chrome Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | 6.2% | — |
| CVE-2018-1025 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge. | 6.2% | — |
| CVE-2020-1036 | CRIT 9.0 | microsoft windows_server_2008 A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is un | 6.2% | — |