IT
56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-36400 HIGH 8.8 microsoft windows_10_1507 Windows HMAC Key Derivation Elevation of Privilege Vulnerability 4.3%
CVE-2020-17061 HIGH 8.8 microsoft sharepoint_foundation Microsoft SharePoint Remote Code Execution Vulnerability 4.3%
CVE-2020-1303 MED 5.5 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context.</p> <p>An attacker could exploit this vu 4.3%
CVE-2019-1213 CRIT 9.8 microsoft windows_server_2008 A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server. An attacker who successfully exploited the vulnerability could run arbitrary code on the DHCP server. To exploit the 4.2%
CVE-2010-1852 MED 4.3 microsoft internet_explorer Microsoft Internet Explorer, when the Invisible Hand extension is enabled, uses cookies during background HTTP requests in a possibly unexpected manner, which might allow remote web servers to identify specific persons and their product searches via HTTP reque 4.2%
CVE-2019-1109 CRIT 9.1 microsoft office A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker who successfully exploited this vulnerability could read or write information in Office documents.The 4.2%
CVE-2019-0796 MED 5.5 microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0805, CVE-2019-0836, CVE 4.2%
CVE-2002-1139 MED 5.0 microsoft windows_98_plus_pack The Compressed Folders feature in Microsoft Windows 98 with Plus! Pack, Windows Me, and Windows XP does not properly check the destination folder during the decompression of ZIP files, which allows attackers to place an executable file in a known location on a 4.2%
CVE-2017-8687 MED 5.5 microsoft windows_10 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabi 4.2%
CVE-2017-8681 MED 5.5 microsoft windows_10 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabi 4.2%
CVE-2017-8680 MED 5.5 microsoft windows_7 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Win3 4.2%
CVE-2017-8678 MED 5.5 microsoft windows_10 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabi 4.2%
CVE-2020-1462 MED 4.3 microsoft edge An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'. 4.2%
CVE-2017-8584 HIGH 7.5 microsoft windows_10 Windows 10 1607 and Windows Server 2016 allow an attacker to execute code remotely via a specially crafted WiFi packet aka "HoloLens Remote Code Execution Vulnerability." 4.2%
CVE-2020-17003 HIGH 7.8 microsoft 3d_viewer <p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>The security update addresses the vulner 4.2%
CVE-2020-16967 HIGH 7.8 microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user i 4.2%
CVE-2020-1496 HIGH 8.8 microsoft 365_apps A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the 4.2%
CVE-2020-1495 HIGH 8.8 microsoft 365_apps A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the 4.2%
CVE-2020-1494 HIGH 8.8 microsoft 365_apps A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the 4.2%
CVE-2024-20683 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 4.2%
CVE-2019-0734 HIGH 8.1 microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresse 4.2%
CVE-2015-2518 MED 6.9 microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted appli 4.2%
CVE-2015-2511 MED 6.9 microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted appli 4.2%
CVE-2020-1504 HIGH 8.8 microsoft excel A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the 4.2%
CVE-2022-21994 HIGH 7.8 microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability 4.2%