IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2009-0229 MED 4.9 microsoft windows_2000 The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability." 3.9%
CVE-2005-4696 LOW 2.1 microsoft windows_xp The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key in plaintext in memory of the explorer process, which allows attackers with access to process memory to steal the keys and access 3.9%
CVE-2020-1557 HIGH 7.3 microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu 3.9%
CVE-2020-1498 HIGH 8.8 microsoft 365_apps A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the 3.9%
CVE-2010-3888 HIGH 7.2 microsoft windows Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers. 3.9%
CVE-2017-0203 MED 4.3 microsoft edge A vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents. An attacker could trick a user into loading a web page with malicious content, aka "Microsoft Edge Security Fea 3.9%
CVE-2000-0036 MED 5.0 microsoft ie Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability. 3.9%
CVE-2006-1476 LOW 2.6 microsoft windows_xp Windows Firewall in Microsoft Windows XP SP2 produces incorrect application block alerts when the application filename is ".exe" (with no characters before the "."), which might allow local user-assisted users to trick a user into unblocking a Trojan horse pro 3.9%
CVE-2024-20656 HIGH 7.8 microsoft visual_studio Visual Studio Elevation of Privilege Vulnerability 3.9%
CVE-2003-0007 MED 5.0 microsoft outlook Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificate 3.9%
CVE-2005-3176 HIGH 7.5 microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection. 3.9%
CVE-2025-50177 HIGH 8.1 microsoft windows_10_1507 Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. 3.9%
CVE-2020-0645 HIGH 7.5 microsoft windows_10 A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers, aka 'Microsoft IIS Server Tampering Vulnerability'. 3.9%
CVE-2021-26423 HIGH 7.5 microsoft .net .NET Core and Visual Studio Denial of Service Vulnerability 3.9%
CVE-2020-0856 MED 6.5 microsoft windows_server_2008 <p>An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited this vulnerability would be able to read sensitive information about the target s 3.9%
CVE-2017-0095 HIGH 7.6 microsoft windows_10 Hyper-V in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This vulnerabilit 3.9%
CVE-2024-21426 HIGH 7.8 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 3.9%
CVE-2023-48315 HIGH 8.8 microsoft azure_rtos_netx_duo Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include p 3.9%
CVE-2017-0164 MED 4.4 microsoft windows_10 A denial of service vulnerability exists in Windows 10 1607 and Windows Server 2016 Active Directory when an authenticated attacker sends malicious search queries, aka "Active Directory Denial of Service Vulnerability." 3.9%
CVE-2017-8491 MED 5.0 microsoft windows_10 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe 3.9%
CVE-2017-8489 MED 5.0 microsoft windows_10 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe 3.9%
CVE-2017-8481 MED 5.0 microsoft windows_10 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe 3.9%
CVE-2017-8479 MED 5.0 microsoft windows_10 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe 3.9%
CVE-2021-1643 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 3.9%
CVE-2017-8633 HIGH 7.5 microsoft windows_10 Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability, aka "Wi 3.9%