IT
56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2001-0507 HIGH 7.2 microsoft internet_information_services IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability. 4.4%
CVE-2016-0152 HIGH 7.8 microsoft windows_server_2008 Internet Information Services (IIS) in Microsoft Windows Vista SP2 and Server 2008 SP2 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows DLL Loading Remote Code Execution Vulnerability." 4.4%
CVE-2020-0909 HIGH 7.5 microsoft windows_10 A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets. To exploit the vulnerability, an attacker would send specially crafted network packets to the Hyper-V Server. The security upd 4.4%
CVE-2005-0047 HIGH 7.2 microsoft windows_2000 Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability." 4.4%
CVE-2020-0875 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system (low-integrity to medium-integrity).</p> <p> 4.4%
CVE-2017-0182 MED 5.8 microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a 4.4%
CVE-2020-16855 MED 5.5 microsoft office <p>An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of 4.4%
CVE-2018-8580 MED 4.3 microsoft sharepoint_server An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosu 4.4%
CVE-2019-1204 MED 4.3 microsoft office An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Out 4.4%
CVE-2026-40364 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. 4.4%
CVE-2019-0716 MED 5.8 microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on 4.4%
CVE-2017-0183 MED 5.8 microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a 4.4%
CVE-2000-0737 MED 4.6 microsoft windows_2000 The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability. 4.4%
CVE-2016-0095 HIGH 7.8 microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application 4.4%
CVE-2022-21883 HIGH 7.5 microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 4.4%
CVE-2018-0890 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists when Active Directory incorrectly applies Network Isolation settings, aka "Active Directory Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. 4.4%
CVE-2021-34520 HIGH 8.1 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 4.4%
CVE-2020-0665 HIGH 8.1 microsoft windows_10 An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privi 4.4%
CVE-2021-34470 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 4.4%
CVE-2023-38143 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 4.4%
CVE-2020-16856 HIGH 7.8 microsoft visual_studio <p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged o 4.4%
CVE-2000-0767 LOW 2.6 microsoft internet_explorer The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability. 4.4%
CVE-2020-1217 HIGH 7.8 microsoft windows_10 An information disclosure vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Information Disclosure Vulnerability'. 4.4%
CVE-2019-0649 HIGH 8.1 microsoft chakracore A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileged Vulnerability'. 4.4%
CVE-2023-28266 MED 5.5 microsoft windows_10_1507 Windows Common Log File System Driver Information Disclosure Vulnerability 4.4%