56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1125 | MED 5.6 | microsoft windows_10 An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, | 4.5% | — |
| CVE-2021-31965 | MED 5.7 | microsoft sharepoint_foundation Microsoft SharePoint Server Information Disclosure Vulnerability | 4.5% | — |
| CVE-2019-0657 | MED 5.9 | microsoft .net_core A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. | 4.5% | — |
| CVE-2024-38100 | HIGH 7.8 | microsoft windows_server_2016 Windows File Explorer Elevation of Privilege Vulnerability | 4.5% | — |
| CVE-2020-1555 | HIGH 8.8 | microsoft chakracore A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the | 4.5% | — |
| CVE-2024-21408 | MED 5.5 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 4.5% | — |
| CVE-2019-0865 | HIGH 7.5 | microsoft windows_10 A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attacker could exploit the vulnerability by creating a specially crafted connection or message.The security update addresses the vulnerability by | 4.5% | — |
| CVE-2019-0811 | HIGH 7.5 | microsoft windows_server_2012 A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS queries, aka 'Windows DNS Server Denial of Service Vulnerability'. | 4.5% | — |
| CVE-2024-43466 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Denial of Service Vulnerability | 4.5% | — |
| CVE-2019-0762 | MED 4.3 | microsoft edge A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'. | 4.5% | — |
| CVE-2020-1228 | HIGH 7.5 | microsoft windows_server_2008 <p>A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive.</p> <p>To exploit the vulnerability, an authenti | 4.5% | — |
| CVE-2024-20653 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Common Log File System Elevation of Privilege Vulnerability | 4.5% | — |
| CVE-2026-24289 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 4.5% | — |
| CVE-2022-37967 | HIGH 7.2 | fedoraproject fedora Windows Kerberos Elevation of Privilege Vulnerability | 4.5% | — |
| CVE-2020-1091 | MED 6.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.</p> <p>Th | 4.5% | — |
| CVE-2019-1157 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.5% | — |
| CVE-2019-1146 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.5% | — |
| CVE-2024-38257 | HIGH 7.5 | microsoft windows_10_1607 Microsoft AllJoyn API Information Disclosure Vulnerability | 4.5% | — |
| CVE-2020-1459 | HIGH 7.5 | microsoft windows_10 An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation." To exploit this vulnerability, an attacker with local privileges would | 4.5% | — |
| CVE-2019-0551 | HIGH 8.4 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows Server 2 | 4.5% | — |
| CVE-2019-0550 | HIGH 8.4 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows 10 Serve | 4.5% | — |
| CVE-2021-30614 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip | 4.5% | — |
| CVE-2020-16911 | HIGH 8.8 | microsoft windows_10 <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could th | 4.5% | — |
| CVE-2020-1432 | MED 4.3 | microsoft internet_explorer An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'. | 4.5% | — |
| CVE-2022-26927 | HIGH 8.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 4.4% | — |