56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1307 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, | 3.8% | — |
| CVE-2015-1725 | HIGH 7.2 | microsoft windows_7 Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local | 3.8% | — |
| CVE-2020-1129 | HIGH 8.8 | microsoft windows_10 <p>A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install prog | 3.8% | — |
| CVE-2022-23271 | MED 6.5 | microsoft dynamics_gp Microsoft Dynamics GP Elevation Of Privilege Vulnerability | 3.8% | — |
| CVE-2018-8314 | MED 4.7 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows fails a check, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, | 3.7% | — |
| CVE-2010-2739 | HIGH 7.2 | microsoft windows_2003_server Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary | 3.7% | — |
| CVE-2001-1122 | LOW 2.1 | microsoft windows_nt Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode. | 3.7% | — |
| CVE-2021-30617 | MED 6.5 | fedoraproject fedora Chromium: CVE-2021-30617 Policy bypass in Blink | 3.7% | — |
| CVE-2020-1012 | HIGH 8.8 | microsoft internet_explorer <p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>There are multiple ways an attacker could | 3.7% | — |
| CVE-2022-21986 | HIGH 7.5 | fedoraproject fedora .NET Denial of Service Vulnerability | 3.7% | — |
| CVE-2024-38059 | HIGH 7.8 | microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability | 3.7% | — |
| CVE-2017-0297 | MED 5.0 | microsoft windows_10 The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially c | 3.7% | — |
| CVE-2020-0728 | MED 5.5 | microsoft windows_10 An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'. | 3.7% | — |
| CVE-2000-0325 | HIGH 7.2 | microsoft jet The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability. | 3.7% | — |
| CVE-2017-8475 | MED 5.0 | microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly in | 3.7% | — |
| CVE-2020-17119 | MED 6.5 | microsoft 365_apps Microsoft Outlook Information Disclosure Vulnerability | 3.7% | — |
| CVE-2024-38141 | HIGH 7.8 | microsoft windows_10_1507 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 3.7% | — |
| CVE-2020-1024 | HIGH 8.8 | microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoin | 3.7% | — |
| CVE-2020-1023 | HIGH 8.8 | microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoin | 3.7% | — |
| CVE-2017-8469 | MED 5.5 | microsoft windows_7 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially | 3.7% | — |
| CVE-2020-1581 | HIGH 7.8 | microsoft 365_apps An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) components handle objects in memory. An attacker who successfully exploited the vulnerability could elevate privileges. The attacker would need to already have t | 3.7% | — |
| CVE-2024-38150 | HIGH 7.8 | microsoft windows_10_21h2 Windows DWM Core Library Elevation of Privilege Vulnerability | 3.7% | — |
| CVE-2022-26815 | HIGH 7.2 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 3.7% | — |
| CVE-2022-26813 | HIGH 7.2 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 3.7% | — |
| CVE-2022-26812 | HIGH 7.2 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 3.7% | — |