56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-1025 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge. | 6.1% | — |
| CVE-2015-2378 | MED 6.9 | microsoft excel Untrusted search path vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel Viewer 2007 SP3, and Office Compatibility Pack SP3 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Microsoft Excel DLL Re | 6.1% | — |
| CVE-1999-0579 | HIGH 10.0 | microsoft windows_nt A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. | 6.1% | — |
| CVE-1999-0577 | HIGH 10.0 | microsoft windows_nt A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. | 6.1% | — |
| CVE-2016-3219 | HIGH 7.8 | microsoft windows_10 The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." | 6.1% | — |
| CVE-2023-35630 | HIGH 8.8 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Remote Code Execution Vulnerability | 6.1% | — |
| CVE-2018-8635 | HIGH 8.8 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka "Microsoft SharePoint Server Elevation of Privilege Vulnerability." This | 6.1% | — |
| CVE-2019-1079 | MED 6.5 | microsoft visual_studio An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'. | 6.1% | — |
| CVE-2020-1445 | MED 5.5 | microsoft 365_apps An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1342. | 6.1% | — |
| CVE-2017-8547 | HIGH 7.5 | microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses o | 6.1% | — |
| CVE-2017-8519 | HIGH 7.5 | microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly access | 6.1% | — |
| CVE-2021-28439 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 6.1% | — |
| CVE-2019-1384 | CRIT 9.9 | microsoft windows_10 A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Featur | 6.1% | — |
| CVE-2007-3658 | MED 5.0 | microsoft register_server Unspecified vulnerability in Microsoft Register Server (REGSVR) allows attackers to cause a denial of service via a crafted DLL library. | 6.1% | — |
| CVE-2022-22034 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 6.1% | — |
| CVE-2019-0678 | MED 6.8 | microsoft edge An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacke | 6.1% | — |
| CVE-2000-1218 | CRIT 9.8 | microsoft windows_2000 The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison | 6.1% | — |
| CVE-2021-34519 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Information Disclosure Vulnerability | 6.1% | — |
| CVE-2017-0273 | MED 5.9 | microsoft windows_10 The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0280. | 6.1% | — |
| CVE-2006-5805 | MED 5.0 | microsoft ie Microsoft Internet Explorer 7 allows remote attackers to cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/invalidcert.htm with the target site as an argument, which displays the site's URL in the address bar | 6.1% | — |
| CVE-2024-43502 | HIGH 7.1 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 6.1% | — |
| CVE-2000-0415 | MED 5.0 | microsoft outlook Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name. | 6.1% | — |
| CVE-2019-1030 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit th | 6.1% | — |
| CVE-2018-1037 | MED 4.3 | microsoft visual_studio An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compiling program database (PDB) files, aka "Microsoft Visual Studio Information Disclosure Vulnerability." This affects Micro | 6.0% | — |
| CVE-2018-8123 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-1021. | 6.0% | — |