IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1389 HIGH 8.4 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CV 4.0%
CVE-2008-4927 MED 4.3 microsoft windows_media_player Microsoft Windows Media Player (WMP) 9.0 through 11 allows user-assisted attackers to cause a denial of service (application crash) via a malformed (1) MIDI or (2) DAT file, related to "MThd Header Parsing." NOTE: the provenance of this information is unknown; 4.0%
CVE-2008-3464 HIGH 7.2 microsoft windows_2003_server afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted appli 4.0%
CVE-2021-27081 HIGH 7.8 microsoft eslint Visual Studio Code ESLint Extension Remote Code Execution Vulnerability 4.0%
CVE-2021-34494 HIGH 8.8 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 4.0%
CVE-2016-0006 HIGH 7.3 microsoft windows_10 The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows 4.0%
CVE-2021-36940 HIGH 7.6 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 4.0%
CVE-2001-1515 HIGH 7.5 microsoft windows_2000 Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended. 4.0%
CVE-2015-6095 MED 4.9 microsoft windows_10 Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles password changes, which allows physically prox 4.0%
CVE-2023-36743 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 4.0%
CVE-2020-0664 MED 6.5 microsoft windows_server_2008 <p>An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited this vulnerability would be able to read sensitive information about the target s 4.0%
CVE-2000-0765 MED 5.1 microsoft excel Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability. 4.0%
CVE-2019-1172 MED 4.3 microsoft windows_10 An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an 4.0%
CVE-2005-2143 MED 5.0 microsoft frontpage Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page. 4.0%
CVE-2015-2370 HIGH 7.2 microsoft windows_2003_server The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 d 4.0%
CVE-2015-6098 HIGH 7.2 microsoft windows_7 Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows NDIS Elevation of 4.0%
CVE-2018-8410 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve 4.0%
CVE-2017-11874 LOW 3.1 microsoft chakracore Microsoft Edge in Microsoft Windows 10 1703, 1709, Windows Server, version 1709, and ChakraCore allows an attacker to bypass Control Flow Guard (CFG) to run arbitrary code on a target system, due to how Microsoft Edge handles accessing memory in code compiled 4.0%
CVE-2020-16873 MED 4.7 microsoft xamarin.forms <p>A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106. This vulnerability could allow an attacker to execute arbitrary Javascript code on a target system.</p> <p>For the a 4.0%
CVE-2021-30623 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30623 Use after free in Bookmarks 4.0%
CVE-2017-8664 HIGH 8.8 microsoft windows_10 Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from a privileged user on a gu 4.0%
CVE-2017-8591 HIGH 7.8 microsoft windows_10 Windows Input Method Editor (IME) in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an remote code execution vulnerability when it fails to properly handle objects in memory, 4.0%
CVE-2019-1205 CRIT 9.8 microsoft office A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context o 4.0%
CVE-2019-0736 CRIT 9.8 microsoft windows_10 A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. To exploit the vul 4.0%
CVE-2025-59199 HIGH 7.8 microsoft windows_10_1809 Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally. 4.0%