IT
56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1443 MED 6.5 microsoft sharepoint_enterprise_server An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint func 5.4%
CVE-2020-16881 HIGH 7.8 microsoft visual_studio_code <p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If 5.4%
CVE-2018-8310 HIGH 7.5 microsoft office A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office. 5.4%
CVE-2023-38144 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 5.4%
CVE-2018-0927 MED 4.3 microsoft edge Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, v 5.4%
CVE-2021-26435 HIGH 8.1 microsoft windows_10 Windows Scripting Engine Memory Corruption Vulnerability 5.3%
CVE-2016-0011 MED 5.4 microsoft sharepoint_foundation Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Secu 5.3%
CVE-2017-8602 MED 6.5 microsoft edge Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a spoofing vulnerability in the way they parse HTTP content, 5.3%
CVE-2019-1301 HIGH 7.5 microsoft .net_core A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'. 5.3%
CVE-2019-1084 MED 6.5 microsoft exchange_server An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when 5.3%
CVE-2023-21752 HIGH 7.1 microsoft windows_10 Windows Backup Service Elevation of Privilege Vulnerability 5.3%
CVE-2017-11794 MED 4.3 microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system, due to how Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique 5.3%
CVE-2009-2510 MED 6.8 microsoft windows_2000 The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not proper 5.3%
CVE-2001-0338 MED 5.1 microsoft internet_explorer Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability." 5.3%
CVE-2018-8150 MED 6.5 microsoft office A security feature bypass vulnerability exists when the Microsoft Outlook attachment block filter does not properly handle attachments, aka "Microsoft Outlook Security Feature Bypass Vulnerability." This affects Microsoft Office. 5.3%
CVE-2019-1313 MED 6.5 microsoft sql_server_management_studio An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1376. 5.3%
CVE-2020-0801 HIGH 8.8 microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0807, CVE-2020-0809, CVE-2020-0869. 5.3%
CVE-2019-1206 HIGH 7.5 microsoft windows_server_2012 A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server. An attacker who successfully exploited the vulnerability could cause the DHCP service to become nonresponsiv 5.3%
CVE-2022-24533 HIGH 8.0 microsoft windows_10 Remote Desktop Protocol Remote Code Execution Vulnerability 5.3%
CVE-2020-1433 MED 6.5 microsoft edge An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF Information Disclosure Vulnerability'. 5.3%
CVE-2021-42298 HIGH 7.8 microsoft malware_protection_engine Microsoft Defender Remote Code Execution Vulnerability 5.3%
CVE-2000-1085 MED 4.6 microsoft data_engine The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an a 5.3%
CVE-2019-1029 MED 5.9 microsoft lync_server A denial of service vulnerability exists in Skype for Business. An attacker who successfully exploited the vulnerability could cause Skype for Business to stop responding. Note that the denial of service would not allow an attacker to execute code or to elevat 5.3%
CVE-2024-30037 MED 5.5 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 5.3%
CVE-2018-8276 MED 6.5 microsoft edge A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows Control Flow Guard (CFG) to be bypassed, aka "Scripting Engine Security Feature Bypass Vulnerability." This affects Microsoft Edge, ChakraCore. 5.3%