56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-11936 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". | 4.2% | — |
| CVE-2010-2744 | HIGH 7.2 | microsoft windows_2003_server The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating | 4.2% | — |
| CVE-2015-2517 | MED 6.9 | microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted appli | 4.2% | — |
| CVE-2004-0979 | MED 4.6 | microsoft ie Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user's intended configura | 4.2% | — |
| CVE-1999-0372 | LOW 2.1 | microsoft backoffice The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. | 4.2% | — |
| CVE-2024-43629 | HIGH 7.8 | microsoft windows_10_1809 Windows DWM Core Library Elevation of Privilege Vulnerability | 4.2% | — |
| CVE-2020-1558 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.2% | — |
| CVE-2024-38228 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 4.2% | — |
| CVE-2007-5493 | MED 4.3 | microsoft windows_mobile The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded. | 4.2% | — |
| CVE-2021-21136 | MED 6.5 | google chrome Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | 4.2% | — |
| CVE-2025-29809 | HIGH 7.1 | microsoft windows_10_1507 Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally. | 4.2% | — |
| CVE-2020-16950 | MED 5.0 | microsoft sharepoint_server <p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To | 4.2% | — |
| CVE-2017-0249 | HIGH 7.3 | microsoft asp.net_model_view_controller An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | 4.2% | — |
| CVE-2017-17689 | MED 5.9 | 9folders nine The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. | 4.2% | — |
| CVE-2022-21848 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 4.2% | — |
| CVE-2021-30616 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30616 Use after free in Media | 4.2% | — |
| CVE-2021-30609 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30609 Use after free in Sign-In | 4.2% | — |
| CVE-2019-1255 | HIGH 7.5 | microsoft forefront_endpoint_protection_2010 A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'. | 4.1% | — |
| CVE-2026-20871 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. | 4.1% | — |
| CVE-2016-7216 | MED 5.5 | microsoft windows_7 The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability." | 4.1% | — |
| CVE-2008-1451 | HIGH 7.2 | microsoft windows_2000 The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability." | 4.1% | — |
| CVE-2021-30610 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30610 Use after free in Extensions API | 4.1% | — |
| CVE-2003-0664 | HIGH 7.5 | microsoft word Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document. | 4.1% | — |
| CVE-2017-8474 | MED 5.0 | microsoft windows_10 The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially c | 4.1% | — |
| CVE-2020-17066 | HIGH 7.8 | microsoft excel Microsoft Excel Remote Code Execution Vulnerability | 4.1% | — |