IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-0720 HIGH 8.0 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted a 3.8%
CVE-2021-24111 HIGH 7.5 microsoft .net_framework .NET Framework Denial of Service Vulnerability 3.8%
CVE-2021-1644 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 3.8%
CVE-2020-17104 HIGH 7.8 microsoft visual_studio_code Visual Studio Code JSHint Extension Remote Code Execution Vulnerability 3.8%
CVE-2020-1153 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user 3.8%
CVE-2020-17017 MED 5.3 microsoft sharepoint_enterprise_server Microsoft SharePoint Information Disclosure Vulnerability 3.8%
CVE-2020-16923 HIGH 7.8 microsoft windows_10 <p>A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.</p> <p>To exploit the vulnerabilit 3.8%
CVE-2023-23396 MED 6.5 microsoft office_online_server Microsoft Excel Denial of Service Vulnerability 3.8%
CVE-2020-1466 HIGH 7.8 microsoft windows_server_2012 A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RD 3.8%
CVE-2017-8508 MED 5.5 microsoft outlook A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats, aka "Microsoft Office Security Feature Bypass Vulnerability". 3.8%
CVE-2016-3252 HIGH 7.3 microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application 3.8%
CVE-2021-42313 CRIT 10.0 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 3.8%
CVE-2019-1140 HIGH 8.8 microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 3.8%
CVE-2016-0175 LOW 3.3 microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to obtain sensitive information about kernel 3.8%
CVE-2020-1285 HIGH 8.4 microsoft windows_10 <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could th 3.8%
CVE-2016-3344 LOW 3.3 microsoft windows_10 The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain sensitive information via a crafted application, aka "Windows Secure Kernel Mode Information Disclosure Vulnerability." 3.8%
CVE-2021-31183 HIGH 7.5 microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability 3.8%
CVE-2019-1220 MED 4.3 microsoft edge A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'. 3.8%
CVE-2024-38140 CRIT 9.8 microsoft windows_10_1507 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability 3.8%
CVE-2021-31962 CRIT 9.4 microsoft windows_10 Kerberos AppContainer Security Feature Bypass Vulnerability 3.8%
CVE-2015-0060 MED 4.7 microsoft windows_7 The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not p 3.8%
CVE-2005-3168 HIGH 7.5 microsoft windows_2000 The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less sec 3.8%
CVE-2022-29130 CRIT 9.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 3.8%
CVE-2019-1264 HIGH 7.8 microsoft office A security feature bypass vulnerability exists when Microsoft Office improperly handles input, aka 'Microsoft Office Security Feature Bypass Vulnerability'. 3.8%
CVE-2005-1791 LOW 2.6 microsoft ie Microsoft Internet Explorer 6 SP2 (6.0.2900.2180) crashes when the user attempts to add a URI to the restricted zone, in which the full domain name of the URI begins with numeric sequences similar to an IP address. NOTE: if there is not an exploit scenario in 3.8%