IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-1716 HIGH 7.8 microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability 3.6%
CVE-2021-1715 HIGH 7.8 microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability 3.6%
CVE-2007-0843 MED 4.6 microsoft windows_2000 The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChan 3.6%
CVE-2020-0761 HIGH 8.8 microsoft windows_server_2008 <p>A remote code execution vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Local System Accou 3.6%
CVE-2020-0718 HIGH 8.8 microsoft windows_server_2008 <p>A remote code execution vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Local System Accou 3.6%
CVE-2023-21688 HIGH 7.8 microsoft windows_10_1507 NT OS Kernel Elevation of Privilege Vulnerability 3.6%
CVE-2019-0909 HIGH 7.5 microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu 3.6%
CVE-2021-26879 HIGH 7.5 microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability 3.6%
CVE-2016-0143 HIGH 7.8 microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application 3.6%
CVE-2012-2993 MED 5.9 microsoft windows_phone_7_firmware Microsoft Windows Phone 7 does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL server for the (1) POP3, (2) IMAP, or (3) SMTP protocol via an arbitrary valid c 3.6%
CVE-2009-0537 MED 4.9 microsoft interix Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to 3.6%
CVE-2024-43498 CRIT 9.8 microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability 3.6%
CVE-2017-8485 MED 5.0 microsoft windows_10 The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a spe 3.6%
CVE-2017-8473 MED 5.0 microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes 3.6%
CVE-2017-8471 MED 5.0 microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when 3.6%
CVE-2020-16971 HIGH 7.4 microsoft azure_sdk_for_java Azure SDK for Java Security Feature Bypass Vulnerability 3.6%
CVE-2018-8308 MED 6.6 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, W 3.6%
CVE-2015-2528 HIGH 7.2 microsoft windows_10 Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Eleva 3.6%
CVE-2021-34524 HIGH 8.1 microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability 3.6%
CVE-2021-23338 MED 6.6 microsoft qlib This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function. 3.6%
CVE-2021-1711 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 3.6%
CVE-2018-8153 MED 5.4 microsoft exchange_server A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Spoofing Vulnerability." This affects Microsoft Exchange Server. 3.6%
CVE-2021-1707 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 3.6%
CVE-2021-1701 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 3.6%
CVE-2021-1700 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 3.6%