56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1389 | HIGH 8.4 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CV | 4.0% | — |
| CVE-2008-4927 | MED 4.3 | microsoft windows_media_player Microsoft Windows Media Player (WMP) 9.0 through 11 allows user-assisted attackers to cause a denial of service (application crash) via a malformed (1) MIDI or (2) DAT file, related to "MThd Header Parsing." NOTE: the provenance of this information is unknown; | 4.0% | — |
| CVE-2008-3464 | HIGH 7.2 | microsoft windows_2003_server afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted appli | 4.0% | — |
| CVE-2021-27081 | HIGH 7.8 | microsoft eslint Visual Studio Code ESLint Extension Remote Code Execution Vulnerability | 4.0% | — |
| CVE-2021-34494 | HIGH 8.8 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 4.0% | — |
| CVE-2016-0006 | HIGH 7.3 | microsoft windows_10 The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows | 4.0% | — |
| CVE-2021-36940 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 4.0% | — |
| CVE-2001-1515 | HIGH 7.5 | microsoft windows_2000 Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended. | 4.0% | — |
| CVE-2015-6095 | MED 4.9 | microsoft windows_10 Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles password changes, which allows physically prox | 4.0% | — |
| CVE-2023-36743 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 4.0% | — |
| CVE-2020-0664 | MED 6.5 | microsoft windows_server_2008 <p>An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited this vulnerability would be able to read sensitive information about the target s | 4.0% | — |
| CVE-2000-0765 | MED 5.1 | microsoft excel Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability. | 4.0% | — |
| CVE-2019-1172 | MED 4.3 | microsoft windows_10 An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an | 4.0% | — |
| CVE-2005-2143 | MED 5.0 | microsoft frontpage Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page. | 4.0% | — |
| CVE-2015-2370 | HIGH 7.2 | microsoft windows_2003_server The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 d | 4.0% | — |
| CVE-2015-6098 | HIGH 7.2 | microsoft windows_7 Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows NDIS Elevation of | 4.0% | — |
| CVE-2018-8410 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve | 4.0% | — |
| CVE-2017-11874 | LOW 3.1 | microsoft chakracore Microsoft Edge in Microsoft Windows 10 1703, 1709, Windows Server, version 1709, and ChakraCore allows an attacker to bypass Control Flow Guard (CFG) to run arbitrary code on a target system, due to how Microsoft Edge handles accessing memory in code compiled | 4.0% | — |
| CVE-2020-16873 | MED 4.7 | microsoft xamarin.forms <p>A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106. This vulnerability could allow an attacker to execute arbitrary Javascript code on a target system.</p> <p>For the a | 4.0% | — |
| CVE-2021-30623 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30623 Use after free in Bookmarks | 4.0% | — |
| CVE-2017-8664 | HIGH 8.8 | microsoft windows_10 Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from a privileged user on a gu | 4.0% | — |
| CVE-2017-8591 | HIGH 7.8 | microsoft windows_10 Windows Input Method Editor (IME) in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an remote code execution vulnerability when it fails to properly handle objects in memory, | 4.0% | — |
| CVE-2019-1205 | CRIT 9.8 | microsoft office A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context o | 4.0% | — |
| CVE-2019-0736 | CRIT 9.8 | microsoft windows_10 A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. To exploit the vul | 4.0% | — |
| CVE-2025-59199 | HIGH 7.8 | microsoft windows_10_1809 Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally. | 4.0% | — |