56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1051 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 3.7% | — |
| CVE-2017-0231 | MED 4.3 | microsoft edge A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Browser Spoofing Vulnerability." | 3.7% | — |
| CVE-2021-41351 | MED 4.3 | microsoft edge Microsoft Edge (Chrome based) Spoofing on IE Mode | 3.7% | — |
| CVE-2021-34469 | HIGH 8.2 | microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability | 3.7% | — |
| CVE-2020-1567 | MED 4.2 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacke | 3.7% | — |
| CVE-2021-43228 | HIGH 7.5 | microsoft windows_10 SymCrypt Denial of Service Vulnerability | 3.7% | — |
| CVE-2021-43219 | HIGH 7.4 | microsoft windows_10 DirectX Graphics Kernel File Denial of Service Vulnerability | 3.7% | — |
| CVE-2021-28465 | HIGH 7.8 | microsoft web_media_extensions Web Media Extensions Remote Code Execution Vulnerability | 3.7% | — |
| CVE-2020-1169 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context.</p> <p>An attacker could exploit this vu | 3.7% | — |
| CVE-2016-0173 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application | 3.7% | — |
| CVE-2019-0735 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Elevation of Privilege Vulnerability'. | 3.7% | — |
| CVE-2016-7188 | HIGH 7.8 | microsoft windows_10 The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulner | 3.7% | — |
| CVE-2016-0094 | HIGH 7.8 | microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application | 3.7% | — |
| CVE-2016-0093 | HIGH 7.8 | microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application | 3.7% | — |
| CVE-2017-8688 | MED 5.5 | microsoft windows_10 Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows information disclosure by the way it discloses ker | 3.7% | — |
| CVE-2017-8679 | MED 5.5 | microsoft windows_10 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabi | 3.7% | — |
| CVE-2017-8677 | MED 5.5 | microsoft windows_10 The Windows GDI+ component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabili | 3.7% | — |
| CVE-2002-0815 | HIGH 7.5 | microsoft internet_explorer The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to | 3.7% | — |
| CVE-2021-31976 | HIGH 7.5 | microsoft windows_10 Server for NFS Information Disclosure Vulnerability | 3.7% | — |
| CVE-2021-31975 | HIGH 7.5 | microsoft windows_10 Server for NFS Information Disclosure Vulnerability | 3.7% | — |
| CVE-2020-1309 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Microsoft Store Runtime Elevation of Privilege Vu | 3.7% | — |
| CVE-2018-0803 | MED 4.2 | microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to access information from one domain and inject it into another domain, due to how Microsoft Edge enforces cross-domain policies, aka "Microsoft Ed | 3.7% | — |
| CVE-2017-0058 | MED 4.7 | microsoft windows_10 A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's syste | 3.7% | — |
| CVE-2018-8159 | MED 5.4 | microsoft exchange_server An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. | 3.7% | — |
| CVE-2018-8152 | MED 5.4 | microsoft exchange_server An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. | 3.7% | — |