IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1265 HIGH 7.5 microsoft yammer A security feature bypass vulnerability exists when Microsoft Yammer App for Android fails to apply the correct Intune MAM Policy.This could allow an attacker to perform functions that are restricted by Intune Policy.The security update addresses the vulnerabi 3.4%
CVE-2022-21843 HIGH 7.5 microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability 3.4%
CVE-2015-1726 HIGH 7.2 microsoft windows_7 Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 3.4%
CVE-2022-26832 HIGH 7.5 microsoft .net_framework .NET Framework Denial of Service Vulnerability 3.4%
CVE-2003-0300 MED 5.0 microsoft outlook_express The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors. 3.4%
CVE-2019-0683 MED 5.9 microsoft windows_7 An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privi 3.4%
CVE-2024-38242 HIGH 7.8 microsoft windows_10_1507 Kernel Streaming Service Driver Elevation of Privilege Vulnerability 3.4%
CVE-2020-16977 HIGH 7.0 microsoft visual_studio_code <p>A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads a Jupyter notebook file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current 3.4%
CVE-2024-29996 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 3.4%
CVE-2020-16862 HIGH 7.1 microsoft dynamics_365 <p>A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in 3.4%
CVE-2006-2334 LOW 2.1 microsoft windows_2000 The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be acce 3.3%
CVE-2025-49718 HIGH 7.5 microsoft sql_server_2019 Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network. 3.3%
CVE-2019-1055 HIGH 7.5 microsoft internet_explorer A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. 3.3%
CVE-2019-1005 HIGH 7.5 microsoft internet_explorer A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. 3.3%
CVE-2021-1721 MED 6.5 microsoft .net .NET Core and Visual Studio Denial of Service Vulnerability 3.3%
CVE-2017-0165 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Windows Elevation of Privilege Vulnerabilit 3.3%
CVE-2015-1723 HIGH 7.2 microsoft windows_7 Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 3.3%
CVE-2015-1674 MED 4.6 microsoft windows_8 The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate an unspecified address, which allows local users to bypass the KASLR protection mechanism, and consequently discover the cng 3.3%
CVE-2001-1347 MED 4.6 microsoft windows_2000 Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of 3.3%
CVE-2017-11831 MED 4.7 microsoft windows_10 Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log on to an affected 3.3%
CVE-2022-30150 HIGH 7.5 microsoft windows_10 Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability 3.3%
CVE-2020-17090 MED 5.3 microsoft windows_10 Microsoft Defender for Endpoint Security Feature Bypass Vulnerability 3.3%
CVE-2023-36767 MED 4.3 microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability 3.3%
CVE-2020-16954 HIGH 7.8 microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If 3.3%
CVE-2020-17123 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 3.3%