58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.478 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-40481 | HIGH 7.1 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 5.9% | — |
| CVE-2018-0932 | MED 4.3 | microsoft edge Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, v | 5.8% | — |
| CVE-2020-16863 | HIGH 7.5 | microsoft windows_7 <p>A denial of service vulnerability exists in Windows Remote Desktop Service when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the Remote Deskto | 5.8% | — |
| CVE-1999-0717 | LOW 2.6 | microsoft excel A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. | 5.8% | — |
| CVE-2007-0685 | LOW 2.6 | microsoft windows_mobile Internet Explorer on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows attackers to cause a denial of service (application crash and device instability) via unspecified vectors, possibly related to a buffer overflow. | 5.8% | — |
| CVE-2017-8643 | MED 4.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to leave a malicious website open during user clipboard activities, due to the way that Microsoft Edge handles clipboard events, aka "Microsoft Edge Infor | 5.8% | — |
| CVE-2017-11899 | CRIT 9.8 | microsoft windows_10 Device Guard in Windows 10 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way untrusted files are handled, aka "Microsoft Windows Security Feature Bypass Vulnerability". | 5.8% | — |
| CVE-1999-0379 | HIGH 7.5 | microsoft backoffice_resource_kit Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting. | 5.8% | — |
| CVE-2018-8238 | HIGH 7.8 | microsoft lync A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared via messages, aka "Skype for Business and Lync Security Feature Bypass Vulnerability." This affects Skype, Microsoft Lync. | 5.8% | — |
| CVE-1999-0728 | HIGH 7.8 | microsoft windows_nt A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them. | 5.8% | — |
| CVE-2018-1037 | MED 4.3 | microsoft visual_studio An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compiling program database (PDB) files, aka "Microsoft Visual Studio Information Disclosure Vulnerability." This affects Micro | 5.8% | — |
| CVE-2019-1299 | MED 6.5 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'. | 5.8% | — |
| CVE-2019-1230 | MED 6.8 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Information Disclosure Vulnerability'. | 5.8% | — |
| CVE-2021-42298 | HIGH 7.8 | microsoft malware_protection_engine Microsoft Defender Remote Code Execution Vulnerability | 5.8% | — |
| CVE-2017-11801 | HIGH 7.5 | microsoft chakracore ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-1 | 5.8% | — |
| CVE-2017-11797 | HIGH 7.5 | microsoft chakracore ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-1 | 5.8% | — |
| CVE-2019-1286 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1252. | 5.8% | — |
| CVE-2019-0972 | MED 6.5 | microsoft windows_10 This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability | 5.8% | — |
| CVE-2024-21306 | MED 5.7 | microsoft windows_10_21h2 Microsoft Bluetooth Driver Spoofing Vulnerability | 5.8% | — |
| CVE-2017-8571 | HIGH 7.8 | microsoft outlook Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a security feature bypass vulnerability due to the way that it handles input, aka "Microsoft Office Outlook Security Fe | 5.8% | — |
| CVE-2018-0771 | MED 4.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows a security feature bypass, due to how Edge handles different-origin requests, aka "Microsoft Edge Security Feature Bypass". | 5.8% | — |
| CVE-1999-1279 | MED 5.0 | microsoft sna_server An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU. | 5.8% | — |
| CVE-1999-0910 | MED 5.0 | microsoft commercial_internet_system Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user. | 5.8% | — |
| CVE-2015-1771 | MED 6.8 | microsoft exchange_server Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnerabilit | 5.8% | — |
| CVE-2019-1443 | MED 6.5 | microsoft sharepoint_enterprise_server An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint func | 5.7% | — |