IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-21880 HIGH 7.5 microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability 3.9%
CVE-2020-17022 HIGH 7.8 microsoft windows_10 <p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code.</p> <p>Exploitation of the vulnerability requires 3.9%
CVE-2020-1252 HIGH 7.8 microsoft windows_10 <p>A remote code execution vulnerability exists when Windows improperly handles objects in memory. To exploit the vulnerability an attacker would have to convince a user to run a specially crafted application.</p> <p>An attacker who successfully exploited this 3.9%
CVE-2019-1218 MED 5.4 microsoft outlook A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim. The attacker who successfu 3.9%
CVE-2021-43224 MED 5.5 microsoft windows_10 Windows Common Log File System Driver Information Disclosure Vulnerability 3.9%
CVE-2020-16957 HIGH 7.8 microsoft 365_apps <p>A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p> <p>An atta 3.9%
CVE-2020-1512 HIGH 7.8 microsoft windows_10 An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. An attack 3.9%
CVE-2001-0090 MED 5.1 microsoft internet_explorer The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the "Browser Print Template" vulnerability. 3.9%
CVE-2022-24507 HIGH 7.8 microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 3.9%
CVE-2002-0340 HIGH 7.5 microsoft windows_media_player Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, which could make it easier for attackers to conduct unauthori 3.9%
CVE-2020-16918 HIGH 7.8 microsoft 365_apps <p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An attacker who successfully exploited the vulnerability would gain execution on a victim system.</p> <p>The security update addresses the vulner 3.9%
CVE-2021-27070 HIGH 7.3 microsoft windows_10 Windows 10 Update Assistant Elevation of Privilege Vulnerability 3.9%
CVE-2020-1378 HIGH 7.5 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. A locally authenticated atta 3.9%
CVE-2019-0668 HIGH 8.8 microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. 3.9%
CVE-2019-0857 MED 6.5 microsoft azure_devops_server A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Spoofing Vulnerability'. 3.9%
CVE-2019-0761 MED 6.5 microsoft internet_explorer A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct Security Zone of requests for specific URLs, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0768. 3.9%
CVE-2022-34728 MED 5.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 3.9%
CVE-2020-17084 HIGH 8.5 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 3.9%
CVE-2013-3661 MED 4.9 microsoft windows_7 The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list 3.9%
CVE-2022-26826 HIGH 7.2 microsoft windows_10 Windows DNS Server Remote Code Execution Vulnerability 3.8%
CVE-2020-1229 MED 4.3 microsoft 365_apps A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'. 3.8%
CVE-2002-0645 HIGH 7.5 microsoft data_engine SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands. 3.8%
CVE-2020-16953 MED 6.5 microsoft sharepoint_enterprise_server <p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To 3.8%
CVE-2020-16948 MED 6.5 microsoft sharepoint_enterprise_server <p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To 3.8%
CVE-2017-0195 MED 5.4 microsoft excel_web_app Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows remote attackers to perform cross-site sc 3.8%