56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-0722 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a | 4.7% | — |
| CVE-2002-1138 | HIGH 7.5 | microsoft data_engine Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite | 4.7% | — |
| CVE-2002-1876 | LOW 2.1 | microsoft exchange_server Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS. | 4.7% | — |
| CVE-1999-0518 | HIGH 7.5 | microsoft windows_95 A NETBIOS/SMB share password is guessable. | 4.7% | — |
| CVE-1999-0499 | HIGH 7.5 | microsoft windows_2000 NETBIOS share information may be published through SNMP registry keys in NT. | 4.7% | — |
| CVE-2024-38258 | MED 6.5 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Information Disclosure Vulnerability | 4.7% | — |
| CVE-2018-0763 | LOW 3.1 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 and 1709 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0839. | 4.7% | — |
| CVE-2020-16930 | HIGH 7.8 | microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If t | 4.7% | — |
| CVE-1999-0827 | LOW 2.6 | microsoft ie By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. | 4.7% | — |
| CVE-2023-24943 | CRIT 9.8 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 4.7% | — |
| CVE-2020-1136 | HIGH 7.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 4.7% | — |
| CVE-2020-1028 | HIGH 7.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 4.7% | — |
| CVE-2020-1234 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting improperly handles objects in memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Elevation of Privi | 4.7% | — |
| CVE-2026-24294 | HIGH 7.8 | microsoft windows_10_1607 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. | 4.7% | — |
| CVE-2020-0765 | MED 5.5 | microsoft remote_desktop_connection_manager An information disclosure vulnerability exists in the Remote Desktop Connection Manager (RDCMan) application when it improperly parses XML input containing a reference to an external entity, aka 'Remote Desktop Connection Manager Information Disclosure Vulnera | 4.7% | — |
| CVE-2020-1319 | HIGH 7.3 | microsoft windows_10 <p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install prog | 4.7% | — |
| CVE-2020-17095 | HIGH 8.5 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 4.7% | — |
| CVE-2020-0869 | HIGH 8.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0807, CVE-2020-0809. | 4.7% | — |
| CVE-2000-0121 | LOW 3.6 | microsoft windows_nt The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability. | 4.7% | — |
| CVE-2023-24939 | HIGH 7.5 | microsoft windows_10_1507 Server for NFS Denial of Service Vulnerability | 4.7% | — |
| CVE-2019-1200 | HIGH 7.8 | microsoft office A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security contex | 4.6% | — |
| CVE-2019-1199 | HIGH 7.8 | microsoft office A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current | 4.6% | — |
| CVE-2019-1461 | MED 6.5 | microsoft office A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory, aka 'Microsoft Word Denial of Service Vulnerability'. | 4.6% | — |
| CVE-2021-36965 | HIGH 8.8 | microsoft windows_10 Windows WLAN AutoConfig Service Remote Code Execution Vulnerability | 4.6% | — |
| CVE-2020-1502 | MED 5.5 | microsoft 365_apps An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, a | 4.6% | — |