56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38085 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 5.3% | — |
| CVE-2019-0804 | MED 6.5 | microsoft walinuxagent An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent Information Disclosure Vulnerability'. | 5.3% | — |
| CVE-2018-0790 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". | 5.3% | — |
| CVE-2017-8504 | MED 4.3 | microsoft edge Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read the URL of a cross-origin request when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information Disclosure Vulnerab | 5.3% | — |
| CVE-2020-1348 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. | 5.2% | — |
| CVE-2000-1081 | MED 4.6 | microsoft data_engine The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an | 5.2% | — |
| CVE-2022-44673 | HIGH 7.0 | microsoft windows_10 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | 5.2% | — |
| CVE-1999-0575 | HIGH 7.5 | microsoft windows_nt A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking. | 5.2% | — |
| CVE-2020-0993 | MED 6.5 | microsoft windows_10 A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'. | 5.2% | — |
| CVE-2022-29142 | HIGH 7.0 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 5.2% | — |
| CVE-2025-55681 | HIGH 7.0 | microsoft windows_10_1809 Out-of-bounds read in Windows DWM allows an authorized attacker to elevate privileges locally. | 5.2% | — |
| CVE-2019-0956 | MED 6.5 | microsoft sharepoint_enterprise_server An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Server Information Disclosure Vulnerability'. | 5.2% | — |
| CVE-2019-1223 | HIGH 7.5 | microsoft windows_10 A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RDP service on th | 5.2% | — |
| CVE-2013-3876 | HIGH 7.1 | microsoft windows_7 DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly veri | 5.2% | — |
| CVE-2019-1432 | MED 6.5 | microsoft windows_7 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1411. | 5.2% | — |
| CVE-2017-11833 | LOW 3.1 | microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to determine the origin of all webpages in the affected browser, due to how Microsoft Edge handles cross-origin request | 5.2% | — |
| CVE-2000-0753 | MED 5.0 | microsoft outlook The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files. | 5.2% | — |
| CVE-1999-0572 | HIGH 9.3 | microsoft windows_2000 .reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks. | 5.2% | — |
| CVE-2017-0064 | MED 6.5 | microsoft internet_explorer A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mixed Content warnings, aka "Internet Explorer Security Feature Bypass Vulnerability." | 5.2% | — |
| CVE-1999-0364 | HIGH 10.0 | fms_inc. total_vb_sourcebook Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data. | 5.2% | — |
| CVE-2022-23267 | HIGH 7.5 | fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability | 5.2% | — |
| CVE-2019-0712 | MED 6.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique fr | 5.2% | — |
| CVE-2003-1107 | MED 5.1 | microsoft windows_media_player The DHTML capability in Microsoft Windows Media Player (WMP) 6.4, 7.0, 7.1, and 9 may run certain URL commands from a security zone that is less trusted than the current zone, which allows attackers to bypass intended access restrictions. | 5.2% | — |
| CVE-2020-1468 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. | 5.2% | — |
| CVE-2017-8498 | MED 4.3 | microsoft edge Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read data not intended to be disclosed when Edge allows JavaScript XML DOM objects to detect installed browser extensions, aka "Microsoft Edge Information Disclosure Vuln | 5.2% | — |