56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-17065 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 4.1% | — |
| CVE-2020-17062 | HIGH 7.8 | microsoft 365_apps Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | 4.1% | — |
| CVE-2018-8490 | HIGH 8.4 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows Server 2 | 4.1% | — |
| CVE-2018-8489 | HIGH 8.4 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windo | 4.1% | — |
| CVE-2003-0232 | HIGH 7.2 | microsoft data_engine Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow. | 4.1% | — |
| CVE-2021-30624 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30624 Use after free in Autofill | 4.1% | — |
| CVE-2021-30620 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink | 4.1% | — |
| CVE-2021-30618 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30618 Inappropriate implementation in DevTools | 4.1% | — |
| CVE-2021-30613 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30613 Use after free in Base internals | 4.1% | — |
| CVE-2021-30607 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30607 Use after free in Permissions | 4.1% | — |
| CVE-2021-30606 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30606 Use after free in Blink | 4.1% | — |
| CVE-2020-16924 | HIGH 7.8 | microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p> <p>An attacker could explo | 4.1% | — |
| CVE-2019-1051 | MED 4.2 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 4.1% | — |
| CVE-2024-21346 | HIGH 7.8 | microsoft windows_11_21h2 Win32k Elevation of Privilege Vulnerability | 4.1% | — |
| CVE-2024-26211 | HIGH 7.8 | microsoft windows_10_1507 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 4.1% | — |
| CVE-2016-7226 | MED 6.1 | microsoft windows_10 Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability." | 4.1% | — |
| CVE-2016-7225 | MED 6.1 | microsoft windows_10 Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability." | 4.1% | — |
| CVE-2016-7224 | MED 6.1 | microsoft windows_10 Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted a | 4.1% | — |
| CVE-2015-6102 | LOW 2.1 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mecha | 4.1% | — |
| CVE-2013-2554 | HIGH 7.5 | microsoft windows_7 Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR and DEP protection mechanisms via unknown vectors, as demonstrated against Firefox by VUPEN during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE | 4.1% | — |
| CVE-2021-28471 | HIGH 7.8 | microsoft visual_studio_code Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability | 4.1% | — |
| CVE-2018-0746 | MED 4.7 | microsoft windows_10 The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handle | 4.1% | — |
| CVE-2019-0974 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.1% | — |
| CVE-2019-0907 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.1% | — |
| CVE-2019-0905 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.1% | — |