56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-0932 | MED 4.3 | microsoft edge Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, v | 6.0% | — |
| CVE-2021-26700 | HIGH 7.8 | microsoft npm Visual Studio Code npm-script Extension Remote Code Execution Vulnerability | 6.0% | — |
| CVE-2016-3221 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application | 5.9% | — |
| CVE-2011-1265 | HIGH 8.8 | bluetooth bluetooth_stack The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via | 5.9% | — |
| CVE-2017-8587 | MED 6.5 | microsoft windows_10 Windows Explorer in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511 allows a denial of service vulnerability when it attempts to open a non-existent file, aka "Windows Explo | 5.9% | — |
| CVE-2002-1872 | HIGH 7.5 | microsoft sql_server Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password. | 5.9% | — |
| CVE-2020-0876 | HIGH 7.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | 5.9% | — |
| CVE-2020-26233 | HIGH 7.3 | microsoft git_credential_manager_core Git Credential Manager Core (GCM Core) is a secure Git credential helper built on .NET Core that runs on Windows and macOS. In Git Credential Manager Core before version 2.0.289, when recursively cloning a Git repository on Windows with submodules, Git will fi | 5.9% | — |
| CVE-2024-38125 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 5.9% | — |
| CVE-2009-2653 | MED 4.6 | microsoft windows_server_2003 The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbit | 5.9% | — |
| CVE-2019-0623 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. | 5.9% | — |
| CVE-2018-0855 | MED 4.3 | microsoft windows_7 The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vu | 5.9% | — |
| CVE-2018-0847 | MED 4.3 | microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow information disclosure, due to how Internet Explore | 5.9% | — |
| CVE-2017-11844 | MED 4.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703, 1709 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure | 5.9% | — |
| CVE-2017-11803 | MED 4.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703, 1709 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure | 5.9% | — |
| CVE-2020-1239 | HIGH 8.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1238. | 5.9% | — |
| CVE-2020-0607 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'. | 5.9% | — |
| CVE-2001-0346 | MED 5.0 | microsoft windows_2000 Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them. | 5.9% | — |
| CVE-1999-0560 | HIGH 10.0 | microsoft windows_nt A system-critical Windows NT file or directory has inappropriate permissions. | 5.9% | — |
| CVE-1999-0226 | HIGH 10.0 | microsoft windows_nt Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service. | 5.9% | — |
| CVE-2025-60724 | CRIT 9.8 | microsoft 365_copilot Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 5.9% | — |
| CVE-1999-0258 | MED 5.0 | microsoft windows_95 Bonk variation of teardrop IP fragmentation denial of service. | 5.9% | — |
| CVE-1999-0275 | MED 5.0 | microsoft windows_nt Denial of service in Windows NT DNS servers by flooding port 53 with too many characters. | 5.9% | — |
| CVE-1999-0292 | MED 5.0 | microsoft windows_nt Denial of service through Winpopup using large user names. | 5.9% | — |
| CVE-2020-16927 | HIGH 7.5 | microsoft windows_10 <p>A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RDP service on | 5.9% | — |