IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.469 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2016-7241 HIGH 7.5 microsoft edge Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." 71.5% —
CVE-2016-3247 HIGH 7.5 microsoft edge Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." 71.5% —
CVE-2011-3400 HIGH 9.3 microsoft windows_server_2003 Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability." 71.4% —
CVE-2019-0547 CRIT 9.8 microsoft windows_10 A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers. 71.4% —
CVE-2017-8755 HIGH 7.5 microsoft edge Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripti 71.3% —
CVE-2001-0540 MED 5.0 microsoft terminal_server Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389. 71.2% —
CVE-2010-1885 HIGH 9.3 microsoft windows_2003_server The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP o 71.2% —
CVE-2021-28480 CRIT 9.8 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 71.2% —
CVE-2020-16952 HIGH 8.6 microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP 71.1% —
CVE-2015-2509 HIGH 9.3 microsoft windows_7 Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Media Center link (mcl) file, aka "Windows Media Center RCE Vulnerability." 71.0% —
CVE-2018-8229 HIGH 7.5 microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique 71.0% —
CVE-2019-0887 HIGH 8.0 microsoft remote_desktop_client A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. 71.0% —
CVE-2015-0096 HIGH 9.3 microsoft windows_7 Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain priv 71.0% —
CVE-2018-8279 HIGH 7.5 microsoft chakracore A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8125, CVE-2018-8262, CVE- 70.7% —
CVE-2014-1762 HIGH 7.5 microsoft internet_explorer Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code with medium-integrity privileges and bypass a sandbox protection mechanism via unknown vectors, as demonstrated by ZDI during a Pwn4Fun comp 70.7% —
CVE-2020-17143 HIGH 8.8 microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability 70.6% —
CVE-2024-38063 CRIT 9.8 microsoft windows_10_1507 Windows TCP/IP Remote Code Execution Vulnerability 70.6% —
CVE-2001-1243 MED 5.0 microsoft internet_information_server Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) rem 70.5% —
CVE-2016-7288 HIGH 7.5 microsoft edge The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-72 70.4% —
CVE-2022-23270 HIGH 8.1 microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability 70.3% —
CVE-2005-0045 HIGH 7.5 microsoft windows_2000 The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 com 70.3% —
CVE-2017-8634 HIGH 7.5 microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Co 70.3% —
CVE-2006-1185 HIGH 7.5 canon network_camera_server_vb101 Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption. 70.3% —
CVE-2019-1184 MED 6.7 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls. An attacker who successfully exploited this vulnerability could potentially set certain items to run at a higher level and thereby elevate 70.2% —
CVE-2011-0105 HIGH 9.3 microsoft excel Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a 70.2% —