56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1443 | MED 6.5 | microsoft sharepoint_enterprise_server An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint func | 5.4% | — |
| CVE-2020-16881 | HIGH 7.8 | microsoft visual_studio_code <p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If | 5.4% | — |
| CVE-2018-8310 | HIGH 7.5 | microsoft office A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office. | 5.4% | — |
| CVE-2023-38144 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 5.4% | — |
| CVE-2018-0927 | MED 4.3 | microsoft edge Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, v | 5.4% | — |
| CVE-2021-26435 | HIGH 8.1 | microsoft windows_10 Windows Scripting Engine Memory Corruption Vulnerability | 5.3% | — |
| CVE-2016-0011 | MED 5.4 | microsoft sharepoint_foundation Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Secu | 5.3% | — |
| CVE-2017-8602 | MED 6.5 | microsoft edge Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a spoofing vulnerability in the way they parse HTTP content, | 5.3% | — |
| CVE-2019-1301 | HIGH 7.5 | microsoft .net_core A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'. | 5.3% | — |
| CVE-2019-1084 | MED 6.5 | microsoft exchange_server An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when | 5.3% | — |
| CVE-2023-21752 | HIGH 7.1 | microsoft windows_10 Windows Backup Service Elevation of Privilege Vulnerability | 5.3% | — |
| CVE-2017-11794 | MED 4.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system, due to how Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique | 5.3% | — |
| CVE-2009-2510 | MED 6.8 | microsoft windows_2000 The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not proper | 5.3% | — |
| CVE-2001-0338 | MED 5.1 | microsoft internet_explorer Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the "Server certificate validation vulnerability." | 5.3% | — |
| CVE-2018-8150 | MED 6.5 | microsoft office A security feature bypass vulnerability exists when the Microsoft Outlook attachment block filter does not properly handle attachments, aka "Microsoft Outlook Security Feature Bypass Vulnerability." This affects Microsoft Office. | 5.3% | — |
| CVE-2019-1313 | MED 6.5 | microsoft sql_server_management_studio An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1376. | 5.3% | — |
| CVE-2020-0801 | HIGH 8.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0807, CVE-2020-0809, CVE-2020-0869. | 5.3% | — |
| CVE-2019-1206 | HIGH 7.5 | microsoft windows_server_2012 A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server. An attacker who successfully exploited the vulnerability could cause the DHCP service to become nonresponsiv | 5.3% | — |
| CVE-2022-24533 | HIGH 8.0 | microsoft windows_10 Remote Desktop Protocol Remote Code Execution Vulnerability | 5.3% | — |
| CVE-2020-1433 | MED 6.5 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF Information Disclosure Vulnerability'. | 5.3% | — |
| CVE-2021-42298 | HIGH 7.8 | microsoft malware_protection_engine Microsoft Defender Remote Code Execution Vulnerability | 5.3% | — |
| CVE-2000-1085 | MED 4.6 | microsoft data_engine The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an a | 5.3% | — |
| CVE-2019-1029 | MED 5.9 | microsoft lync_server A denial of service vulnerability exists in Skype for Business. An attacker who successfully exploited the vulnerability could cause Skype for Business to stop responding. Note that the denial of service would not allow an attacker to execute code or to elevat | 5.3% | — |
| CVE-2024-30037 | MED 5.5 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 5.3% | — |
| CVE-2018-8276 | MED 6.5 | microsoft edge A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows Control Flow Guard (CFG) to be bypassed, aka "Scripting Engine Security Feature Bypass Vulnerability." This affects Microsoft Edge, ChakraCore. | 5.3% | — |