56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2001-1219 | MED 5.0 | microsoft internet_explorer Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location. | 6.0% | — |
| CVE-2017-0192 | MED 4.3 | microsoft windows_10 The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gai | 6.0% | — |
| CVE-1999-0179 | MED 5.0 | microsoft windows_95 Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share. | 6.0% | — |
| CVE-2019-1006 | HIGH 7.5 | microsoft .net_framework An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'. | 6.0% | — |
| CVE-2014-2781 | HIGH 7.6 | microsoft windows_7 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the exchange of keyboard and mouse data between programs at different | 6.0% | — |
| CVE-1999-0590 | HIGH 10.0 | apple macos A system does not present an appropriate legal message or warning to a user who is accessing it. | 6.0% | — |
| CVE-2024-38241 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming Service Driver Elevation of Privilege Vulnerability | 6.0% | — |
| CVE-2017-8542 | MED 5.5 | microsoft forefront_security The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a | 6.0% | — |
| CVE-2017-8539 | MED 5.5 | microsoft forefront_security The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a | 6.0% | — |
| CVE-2016-3232 | MED 5.0 | microsoft windows_server_2012 The Virtual PCI (VPCI) virtual service provider in Microsoft Windows Server 2012 Gold and R2 allows local users to obtain sensitive information from uninitialized memory locations via a crafted application, aka "Windows Virtual PCI Information Disclosure Vulne | 6.0% | — |
| CVE-2017-8659 | MED 4.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system due to the Chakra scripting engine not properly handling objects in memory, aka "Scripting Engine Information Disclosure Vulnerability" | 6.0% | — |
| CVE-1999-0537 | HIGH 7.5 | microsoft internet_explorer A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc. | 6.0% | — |
| CVE-2021-40486 | HIGH 7.8 | microsoft office Microsoft Word Remote Code Execution Vulnerability | 6.0% | — |
| CVE-2025-53145 | HIGH 8.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | 6.0% | — |
| CVE-2025-53144 | HIGH 8.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | 6.0% | — |
| CVE-2003-0301 | MED 5.0 | microsoft outlook_express The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors. | 6.0% | — |
| CVE-1999-0119 | HIGH 10.0 | microsoft windows_nt Windows NT 4.0 beta allows users to read and delete shares. | 6.0% | — |
| CVE-1999-0570 | HIGH 10.0 | microsoft windows_nt Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. | 6.0% | — |
| CVE-1999-0535 | HIGH 10.0 | microsoft windows_2000 A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. | 6.0% | — |
| CVE-2020-1045 | HIGH 7.5 | fedoraproject fedora <p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name bei | 6.0% | — |
| CVE-2018-0907 | HIGH 7.8 | microsoft excel Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, Microsoft Excel 2013 SP1, Microsoft Excel 2016, Microsoft Office 2016 Click-to-Run and Microsoft Office 2016 for Mac allow a security feature bypass vulnerability due to how macro settings are enforced, aka " | 6.0% | — |
| CVE-2008-0074 | HIGH 7.2 | microsoft internet_information_server Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders. | 6.0% | — |
| CVE-2014-0319 | HIGH 7.1 | microsoft silverlight Microsoft Silverlight 5 before 5.1.30214.0 and Silverlight 5 Developer Runtime before 5.1.30214.0 allow attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors, aka "Silverlight DEP/ASLR Bypass Vulnerability." | 6.0% | — |
| CVE-2002-0718 | HIGH 7.5 | microsoft content_management_server Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function." | 6.0% | — |
| CVE-2001-0712 | HIGH 7.5 | microsoft internet_explorer The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support script | 6.0% | — |