56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-0576 | HIGH 7.5 | microsoft windows_nt A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. | 4.9% | — |
| CVE-2019-1089 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an RPC request. To exploit this vulnerability, a low level authenticated attacker could run a specially crafted application. The security upda | 4.9% | — |
| CVE-2021-1723 | HIGH 7.5 | fedoraproject fedora ASP.NET Core and Visual Studio Denial of Service Vulnerability | 4.9% | — |
| CVE-2020-1583 | HIGH 8.8 | microsoft 365_apps An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, a | 4.9% | — |
| CVE-2020-0997 | HIGH 7.8 | microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user i | 4.9% | — |
| CVE-2016-0141 | MED 6.5 | microsoft office The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certificate-store private key during a document-save operation, which allows attackers to obtain sensitive information via unspecified vectors, aka "Microsoft Informati | 4.9% | — |
| CVE-2016-3256 | MED 5.0 | microsoft windows_10 Microsoft Windows 10 Gold and 1511 allows local users to bypass the Secure Kernel Mode protection mechanism and obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability." | 4.9% | — |
| CVE-1999-0331 | HIGH 7.5 | microsoft internet_explorer Buffer overflow in Internet Explorer 4.0(1). | 4.9% | — |
| CVE-1999-0391 | HIGH 7.5 | microsoft terminal_server The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. | 4.9% | — |
| CVE-2019-1411 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1432. | 4.9% | — |
| CVE-2019-1034 | HIGH 7.8 | microsoft office A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context o | 4.9% | — |
| CVE-2020-26870 | MED 6.1 | cure53 dompurify Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements. | 4.9% | — |
| CVE-2018-8578 | MED 4.3 | microsoft sharepoint_enterprise_server An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint. | 4.9% | — |
| CVE-2021-31198 | HIGH 7.8 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 4.9% | — |
| CVE-2017-8490 | MED 5.0 | microsoft windows_10 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe | 4.9% | — |
| CVE-2023-36799 | MED 6.5 | microsoft .net .NET Core and Visual Studio Denial of Service Vulnerability | 4.9% | — |
| CVE-2020-16968 | HIGH 7.8 | microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user i | 4.9% | — |
| CVE-2022-23279 | HIGH 7.0 | microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability | 4.9% | — |
| CVE-2020-0660 | HIGH 7.5 | microsoft windows_10 A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'. | 4.9% | — |
| CVE-2019-1201 | HIGH 7.8 | microsoft office A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context o | 4.9% | — |
| CVE-2018-0976 | MED 5.3 | microsoft windows_10 A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka "Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability." This affects W | 4.9% | — |
| CVE-2024-26234 | MED 6.7 | microsoft windows_10_1507 Proxy Driver Spoofing Vulnerability | 4.9% | — |
| CVE-2020-1034 | MED 6.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the vulnerability, a locall | 4.9% | — |
| CVE-2018-8244 | MED 6.5 | microsoft office An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka "Microsoft Outlook Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Outlook. | 4.9% | — |
| CVE-2019-1183 | HIGH 8.8 | microsoft windows_10 This information is being revised to indicate that this CVE (CVE-2019-1183) is fully mitigated by the security updates for the vulnerability discussed in CVE-2019-1194. No update is required. | 4.8% | — |