IT
56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2017-11936 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". 4.2%
CVE-2010-2744 HIGH 7.2 microsoft windows_2003_server The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating 4.2%
CVE-2015-2517 MED 6.9 microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted appli 4.2%
CVE-2004-0979 MED 4.6 microsoft ie Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user's intended configura 4.2%
CVE-1999-0372 LOW 2.1 microsoft backoffice The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. 4.2%
CVE-2024-43629 HIGH 7.8 microsoft windows_10_1809 Windows DWM Core Library Elevation of Privilege Vulnerability 4.2%
CVE-2020-1558 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu 4.2%
CVE-2024-38228 HIGH 7.2 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 4.2%
CVE-2007-5493 MED 4.3 microsoft windows_mobile The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded. 4.2%
CVE-2021-21136 MED 6.5 google chrome Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. 4.2%
CVE-2025-29809 HIGH 7.1 microsoft windows_10_1507 Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally. 4.2%
CVE-2020-16950 MED 5.0 microsoft sharepoint_server <p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To 4.2%
CVE-2017-0249 HIGH 7.3 microsoft asp.net_model_view_controller An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. 4.2%
CVE-2017-17689 MED 5.9 9folders nine The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. 4.2%
CVE-2022-21848 HIGH 7.5 microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 4.2%
CVE-2021-30616 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30616 Use after free in Media 4.2%
CVE-2021-30609 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30609 Use after free in Sign-In 4.2%
CVE-2019-1255 HIGH 7.5 microsoft forefront_endpoint_protection_2010 A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'. 4.1%
CVE-2026-20871 HIGH 7.8 microsoft windows_10_21h2 Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. 4.1%
CVE-2016-7216 MED 5.5 microsoft windows_7 The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability." 4.1%
CVE-2008-1451 HIGH 7.2 microsoft windows_2000 The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability." 4.1%
CVE-2021-30610 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30610 Use after free in Extensions API 4.1%
CVE-2003-0664 HIGH 7.5 microsoft word Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document. 4.1%
CVE-2017-8474 MED 5.0 microsoft windows_10 The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially c 4.1%
CVE-2020-17066 HIGH 7.8 microsoft excel Microsoft Excel Remote Code Execution Vulnerability 4.1%