56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2001-0337 | MED 5.0 | microsoft internet_information_server The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests. | 5.0% | — |
| CVE-1999-0228 | MED 5.0 | microsoft windows_nt Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT. | 5.0% | — |
| CVE-2022-21974 | HIGH 7.8 | microsoft windows_10 Roaming Security Rights Management Services Remote Code Execution Vulnerability | 5.0% | — |
| CVE-2015-2374 | LOW 3.3 | microsoft windows_2003_server The Netlogon service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2 does not properly implement domain-controller communication, which allows remote attackers to discover credentials by | 5.0% | — |
| CVE-2024-29195 | MED 6.0 | microsoft azure_c_shared_utility The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocatio | 5.0% | — |
| CVE-2017-0300 | MED 5.0 | microsoft windows_10 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe | 5.0% | — |
| CVE-2017-0100 | HIGH 7.8 | microsoft windows_10 A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows local users to gain privileges via a crafted applica | 5.0% | — |
| CVE-2021-26902 | HIGH 7.8 | microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability | 5.0% | — |
| CVE-2019-0877 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0851, CVE-2 | 4.9% | — |
| CVE-2010-0652 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote HTTP servers to obtain sensitive information via a crafted do | 4.9% | — |
| CVE-2019-1126 | MED 5.3 | microsoft windows_server_2012 A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a specially crafted application, which would | 4.9% | — |
| CVE-2019-0995 | HIGH 8.8 | microsoft internet_explorer A security feature bypass vulnerability exists when urlmon.dll improperly handles certain Mark of the Web queries, aka 'Internet Explorer Security Feature Bypass Vulnerability'. | 4.9% | — |
| CVE-1999-0987 | HIGH 10.0 | microsoft windows_nt Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name. | 4.9% | — |
| CVE-2022-29145 | HIGH 7.5 | fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability | 4.9% | — |
| CVE-2019-0981 | HIGH 7.5 | microsoft .net_core A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980. | 4.9% | — |
| CVE-2019-0980 | HIGH 7.5 | microsoft .net_core A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981. | 4.9% | — |
| CVE-2021-43209 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 4.9% | — |
| CVE-2020-16894 | HIGH 7.7 | microsoft windows_10 <p>A denial of service vulnerability exists when Windows Network Address Translation (NAT) on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could caus | 4.9% | — |
| CVE-2019-0932 | MED 5.9 | microsoft skype An information disclosure vulnerability exists in Skype for Android, aka 'Skype for Android Information Disclosure Vulnerability'. | 4.9% | — |
| CVE-2005-4269 | HIGH 7.8 | microsoft ie mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Micro | 4.9% | — |
| CVE-2009-2196 | MED 5.0 | apple mac_os_x Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors. | 4.9% | — |
| CVE-2018-8113 | MED 6.5 | microsoft internet_explorer A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (MOTW), aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11. | 4.9% | — |
| CVE-2020-1585 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install program | 4.9% | — |
| CVE-2023-36439 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 4.9% | — |
| CVE-2025-29794 | HIGH 8.8 | microsoft sharepoint_enterprise_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 4.9% | — |