IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-1051 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu 3.7%
CVE-2017-0231 MED 4.3 microsoft edge A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Browser Spoofing Vulnerability." 3.7%
CVE-2021-41351 MED 4.3 microsoft edge Microsoft Edge (Chrome based) Spoofing on IE Mode 3.7%
CVE-2021-34469 HIGH 8.2 microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability 3.7%
CVE-2020-1567 MED 4.2 microsoft internet_explorer A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacke 3.7%
CVE-2021-43228 HIGH 7.5 microsoft windows_10 SymCrypt Denial of Service Vulnerability 3.7%
CVE-2021-43219 HIGH 7.4 microsoft windows_10 DirectX Graphics Kernel File Denial of Service Vulnerability 3.7%
CVE-2021-28465 HIGH 7.8 microsoft web_media_extensions Web Media Extensions Remote Code Execution Vulnerability 3.7%
CVE-2020-1169 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context.</p> <p>An attacker could exploit this vu 3.7%
CVE-2016-0173 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application 3.7%
CVE-2019-0735 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Elevation of Privilege Vulnerability'. 3.7%
CVE-2016-7188 HIGH 7.8 microsoft windows_10 The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulner 3.7%
CVE-2016-0094 HIGH 7.8 microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application 3.7%
CVE-2016-0093 HIGH 7.8 microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application 3.7%
CVE-2017-8688 MED 5.5 microsoft windows_10 Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows information disclosure by the way it discloses ker 3.7%
CVE-2017-8679 MED 5.5 microsoft windows_10 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabi 3.7%
CVE-2017-8677 MED 5.5 microsoft windows_10 The Windows GDI+ component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabili 3.7%
CVE-2002-0815 HIGH 7.5 microsoft internet_explorer The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to 3.7%
CVE-2021-31976 HIGH 7.5 microsoft windows_10 Server for NFS Information Disclosure Vulnerability 3.7%
CVE-2021-31975 HIGH 7.5 microsoft windows_10 Server for NFS Information Disclosure Vulnerability 3.7%
CVE-2020-1309 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Microsoft Store Runtime Elevation of Privilege Vu 3.7%
CVE-2018-0803 MED 4.2 microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to access information from one domain and inject it into another domain, due to how Microsoft Edge enforces cross-domain policies, aka "Microsoft Ed 3.7%
CVE-2017-0058 MED 4.7 microsoft windows_10 A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's syste 3.7%
CVE-2018-8159 MED 5.4 microsoft exchange_server An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. 3.7%
CVE-2018-8152 MED 5.4 microsoft exchange_server An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. 3.7%