58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.478 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1233 | HIGH 7.5 | microsoft exchange_server A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Denial of Service Vulnerability'. | 6.2% | — |
| CVE-2017-11916 | HIGH 7.5 | microsoft chakracore ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, | 6.2% | — |
| CVE-2017-11878 | HIGH 7.8 | microsoft excel Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Compatibility Pack Service Pack 3, and Microsoft Excel Viewer 2007 Ser | 6.2% | — |
| CVE-2016-3266 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl | 6.2% | — |
| CVE-2020-0738 | HIGH 8.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. | 6.1% | — |
| CVE-2021-34519 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Information Disclosure Vulnerability | 6.1% | — |
| CVE-2015-2378 | MED 6.9 | microsoft excel Untrusted search path vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel Viewer 2007 SP3, and Office Compatibility Pack SP3 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Microsoft Excel DLL Re | 6.1% | — |
| CVE-2016-3219 | HIGH 7.8 | microsoft windows_10 The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." | 6.1% | — |
| CVE-2023-35630 | HIGH 8.8 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | 6.1% | — |
| CVE-2018-8635 | HIGH 8.8 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka "Microsoft SharePoint Server Elevation of Privilege Vulnerability." This | 6.1% | — |
| CVE-2019-1079 | MED 6.5 | microsoft visual_studio An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'. | 6.1% | — |
| CVE-2020-1445 | MED 5.5 | microsoft 365_apps An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1342. | 6.1% | — |
| CVE-2017-8547 | HIGH 7.5 | microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses o | 6.1% | — |
| CVE-2017-8519 | HIGH 7.5 | microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly access | 6.1% | — |
| CVE-2018-8325 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8289, CVE-2018-8297, CVE-2018-8 | 6.1% | — |
| CVE-2021-28439 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 6.1% | — |
| CVE-2007-3658 | MED 5.0 | microsoft register_server Unspecified vulnerability in Microsoft Register Server (REGSVR) allows attackers to cause a denial of service via a crafted DLL library. | 6.1% | — |
| CVE-2018-8123 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-1021. | 6.1% | — |
| CVE-2018-0987 | MED 4.3 | microsoft internet_explorer An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Inter | 6.1% | — |
| CVE-2019-0678 | MED 6.8 | microsoft edge An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacke | 6.1% | — |
| CVE-1999-0119 | HIGH 10.0 | microsoft windows_nt Windows NT 4.0 beta allows users to read and delete shares. | 6.1% | — |
| CVE-1999-0570 | HIGH 10.0 | microsoft windows_nt Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. | 6.1% | — |
| CVE-1999-0535 | HIGH 10.0 | microsoft windows_2000 A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. | 6.1% | — |
| CVE-2017-0273 | MED 5.9 | microsoft windows_10 The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0280. | 6.1% | — |
| CVE-2019-1030 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit th | 6.1% | — |