IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.478 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-40481 HIGH 7.1 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 5.9% —
CVE-2018-0932 MED 4.3 microsoft edge Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, v 5.8% —
CVE-2020-16863 HIGH 7.5 microsoft windows_7 <p>A denial of service vulnerability exists in Windows Remote Desktop Service when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the Remote Deskto 5.8% —
CVE-1999-0717 LOW 2.6 microsoft excel A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. 5.8% —
CVE-2007-0685 LOW 2.6 microsoft windows_mobile Internet Explorer on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows attackers to cause a denial of service (application crash and device instability) via unspecified vectors, possibly related to a buffer overflow. 5.8% —
CVE-2017-8643 MED 4.3 microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to leave a malicious website open during user clipboard activities, due to the way that Microsoft Edge handles clipboard events, aka "Microsoft Edge Infor 5.8% —
CVE-2017-11899 CRIT 9.8 microsoft windows_10 Device Guard in Windows 10 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way untrusted files are handled, aka "Microsoft Windows Security Feature Bypass Vulnerability". 5.8% —
CVE-1999-0379 HIGH 7.5 microsoft backoffice_resource_kit Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting. 5.8% —
CVE-2018-8238 HIGH 7.8 microsoft lync A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared via messages, aka "Skype for Business and Lync Security Feature Bypass Vulnerability." This affects Skype, Microsoft Lync. 5.8% —
CVE-1999-0728 HIGH 7.8 microsoft windows_nt A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them. 5.8% —
CVE-2018-1037 MED 4.3 microsoft visual_studio An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compiling program database (PDB) files, aka "Microsoft Visual Studio Information Disclosure Vulnerability." This affects Micro 5.8% —
CVE-2019-1299 MED 6.5 microsoft edge An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'. 5.8% —
CVE-2019-1230 MED 6.8 microsoft windows_10 An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Information Disclosure Vulnerability'. 5.8% —
CVE-2021-42298 HIGH 7.8 microsoft malware_protection_engine Microsoft Defender Remote Code Execution Vulnerability 5.8% —
CVE-2017-11801 HIGH 7.5 microsoft chakracore ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-1 5.8% —
CVE-2017-11797 HIGH 7.5 microsoft chakracore ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-1 5.8% —
CVE-2019-1286 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1252. 5.8% —
CVE-2019-0972 MED 6.5 microsoft windows_10 This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability 5.8% —
CVE-2024-21306 MED 5.7 microsoft windows_10_21h2 Microsoft Bluetooth Driver Spoofing Vulnerability 5.8% —
CVE-2017-8571 HIGH 7.8 microsoft outlook Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a security feature bypass vulnerability due to the way that it handles input, aka "Microsoft Office Outlook Security Fe 5.8% —
CVE-2018-0771 MED 4.3 microsoft edge Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows a security feature bypass, due to how Edge handles different-origin requests, aka "Microsoft Edge Security Feature Bypass". 5.8% —
CVE-1999-1279 MED 5.0 microsoft sna_server An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU. 5.8% —
CVE-1999-0910 MED 5.0 microsoft commercial_internet_system Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user. 5.8% —
CVE-2015-1771 MED 6.8 microsoft exchange_server Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnerabilit 5.8% —
CVE-2019-1443 MED 6.5 microsoft sharepoint_enterprise_server An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint func 5.7% —