IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.478 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2017-11856 HIGH 7.5 microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain t 5.6% —
CVE-2018-0597 HIGH 7.8 microsoft visual_studio_code Untrusted search path vulnerability in the installer of Visual Studio Code allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. 5.6% —
CVE-2018-0596 HIGH 7.8 microsoft visual_studio_community Untrusted search path vulnerability in the installer of Visual Studio Community allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. 5.6% —
CVE-2018-0595 HIGH 7.8 microsoft skype Untrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. 5.6% —
CVE-2018-0594 HIGH 7.8 microsoft skype Untrusted search path vulnerability in Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. 5.6% —
CVE-2018-0593 HIGH 7.8 microsoft onedrive Untrusted search path vulnerability in the installer of Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. 5.6% —
CVE-2018-0592 HIGH 7.8 microsoft onedrive Untrusted search path vulnerability in Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. 5.6% —
CVE-1999-0519 HIGH 7.5 microsoft outlook A NETBIOS/SMB share password is the default, null, or missing. 5.6% —
CVE-2000-1104 HIGH 7.5 microsoft internet_information_server Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the 5.6% —
CVE-2007-4356 HIGH 9.3 microsoft internet_explorer Microsoft Internet Explorer 6 and 7 embeds FTP credentials in HTML files that are retrieved during an FTP session, which allows context-dependent attackers to obtain sensitive information by reading the HTML source, as demonstrated by a (1) .htm, (2) .html, or 5.6% —
CVE-2002-0615 HIGH 7.5 microsoft excel The Windows Media Active Playlist in Microsoft Windows Media Player 7.1 stores information in a well known location on the local file system, allowing attackers to execute HTML scripts in the Local Computer zone, aka "Media Playback Script Invocation". 5.6% —
CVE-2020-0809 HIGH 8.8 microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0807, CVE-2020-0869. 5.6% —
CVE-2020-0807 HIGH 8.8 microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0809, CVE-2020-0869. 5.6% —
CVE-2018-8276 MED 6.5 microsoft edge A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows Control Flow Guard (CFG) to be bypassed, aka "Scripting Engine Security Feature Bypass Vulnerability." This affects Microsoft Edge, ChakraCore. 5.6% —
CVE-2018-8126 HIGH 8.8 microsoft internet_explorer A security feature bypass vulnerability exists when Internet Explorer fails to validate User Mode Code Integrity (UMCI) policies, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11. 5.6% —
CVE-2022-24533 HIGH 8.0 microsoft windows_10 Remote Desktop Protocol Remote Code Execution Vulnerability 5.6% —
CVE-2023-38159 HIGH 7.0 microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability 5.6% —
CVE-2021-30615 MED 6.5 fedoraproject fedora Chromium: CVE-2021-30615 Cross-origin data leak in Navigation 5.6% —
CVE-2018-8452 MED 4.3 microsoft chakracore An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aka "Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edg 5.6% —
CVE-2018-8558 MED 6.5 microsoft office An information disclosure vulnerability exists when Microsoft Outlook fails to respect "Default link type" settings configured via the SharePoint Online Admin Center, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus 5.6% —
CVE-2023-35382 HIGH 7.8 microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 5.6% —
CVE-2019-0704 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0703, CVE-2019-0821. 5.6% —
CVE-2011-2009 HIGH 9.3 microsoft windows_7 Untrusted search path vulnerability in Windows Media Center in Microsoft Windows Vista SP2 and Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista, allows local users to gain privileges via a Trojan horse DLL in the current working direc 5.6% —
CVE-2019-1432 MED 6.5 microsoft windows_7 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1411. 5.6% —
CVE-1999-0360 HIGH 7.2 microsoft site_server MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely. 5.6% —