IT
56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2001-1219 MED 5.0 microsoft internet_explorer Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location. 6.0%
CVE-2017-0192 MED 4.3 microsoft windows_10 The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gai 6.0%
CVE-1999-0179 MED 5.0 microsoft windows_95 Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share. 6.0%
CVE-2019-1006 HIGH 7.5 microsoft .net_framework An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'. 6.0%
CVE-2014-2781 HIGH 7.6 microsoft windows_7 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the exchange of keyboard and mouse data between programs at different 6.0%
CVE-1999-0590 HIGH 10.0 apple macos A system does not present an appropriate legal message or warning to a user who is accessing it. 6.0%
CVE-2024-38241 HIGH 7.8 microsoft windows_10_1507 Kernel Streaming Service Driver Elevation of Privilege Vulnerability 6.0%
CVE-2017-8542 MED 5.5 microsoft forefront_security The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a 6.0%
CVE-2017-8539 MED 5.5 microsoft forefront_security The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a 6.0%
CVE-2016-3232 MED 5.0 microsoft windows_server_2012 The Virtual PCI (VPCI) virtual service provider in Microsoft Windows Server 2012 Gold and R2 allows local users to obtain sensitive information from uninitialized memory locations via a crafted application, aka "Windows Virtual PCI Information Disclosure Vulne 6.0%
CVE-2017-8659 MED 4.3 microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system due to the Chakra scripting engine not properly handling objects in memory, aka "Scripting Engine Information Disclosure Vulnerability" 6.0%
CVE-1999-0537 HIGH 7.5 microsoft internet_explorer A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc. 6.0%
CVE-2021-40486 HIGH 7.8 microsoft office Microsoft Word Remote Code Execution Vulnerability 6.0%
CVE-2025-53145 HIGH 8.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. 6.0%
CVE-2025-53144 HIGH 8.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. 6.0%
CVE-2003-0301 MED 5.0 microsoft outlook_express The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors. 6.0%
CVE-1999-0119 HIGH 10.0 microsoft windows_nt Windows NT 4.0 beta allows users to read and delete shares. 6.0%
CVE-1999-0570 HIGH 10.0 microsoft windows_nt Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. 6.0%
CVE-1999-0535 HIGH 10.0 microsoft windows_2000 A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. 6.0%
CVE-2020-1045 HIGH 7.5 fedoraproject fedora <p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name bei 6.0%
CVE-2018-0907 HIGH 7.8 microsoft excel Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, Microsoft Excel 2013 SP1, Microsoft Excel 2016, Microsoft Office 2016 Click-to-Run and Microsoft Office 2016 for Mac allow a security feature bypass vulnerability due to how macro settings are enforced, aka " 6.0%
CVE-2008-0074 HIGH 7.2 microsoft internet_information_server Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders. 6.0%
CVE-2014-0319 HIGH 7.1 microsoft silverlight Microsoft Silverlight 5 before 5.1.30214.0 and Silverlight 5 Developer Runtime before 5.1.30214.0 allow attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors, aka "Silverlight DEP/ASLR Bypass Vulnerability." 6.0%
CVE-2002-0718 HIGH 7.5 microsoft content_management_server Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function." 6.0%
CVE-2001-0712 HIGH 7.5 microsoft internet_explorer The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support script 6.0%