IT
56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-17065 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 4.1%
CVE-2020-17062 HIGH 7.8 microsoft 365_apps Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability 4.1%
CVE-2018-8490 HIGH 8.4 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows Server 2 4.1%
CVE-2018-8489 HIGH 8.4 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windo 4.1%
CVE-2003-0232 HIGH 7.2 microsoft data_engine Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow. 4.1%
CVE-2021-30624 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30624 Use after free in Autofill 4.1%
CVE-2021-30620 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink 4.1%
CVE-2021-30618 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30618 Inappropriate implementation in DevTools 4.1%
CVE-2021-30613 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30613 Use after free in Base internals 4.1%
CVE-2021-30607 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30607 Use after free in Permissions 4.1%
CVE-2021-30606 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30606 Use after free in Blink 4.1%
CVE-2020-16924 HIGH 7.8 microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p> <p>An attacker could explo 4.1%
CVE-2019-1051 MED 4.2 microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 4.1%
CVE-2024-21346 HIGH 7.8 microsoft windows_11_21h2 Win32k Elevation of Privilege Vulnerability 4.1%
CVE-2024-26211 HIGH 7.8 microsoft windows_10_1507 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 4.1%
CVE-2016-7226 MED 6.1 microsoft windows_10 Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability." 4.1%
CVE-2016-7225 MED 6.1 microsoft windows_10 Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability." 4.1%
CVE-2016-7224 MED 6.1 microsoft windows_10 Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted a 4.1%
CVE-2015-6102 LOW 2.1 microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mecha 4.1%
CVE-2013-2554 HIGH 7.5 microsoft windows_7 Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR and DEP protection mechanisms via unknown vectors, as demonstrated against Firefox by VUPEN during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE 4.1%
CVE-2021-28471 HIGH 7.8 microsoft visual_studio_code Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability 4.1%
CVE-2018-0746 MED 4.7 microsoft windows_10 The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handle 4.1%
CVE-2019-0974 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu 4.1%
CVE-2019-0907 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu 4.1%
CVE-2019-0905 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu 4.1%