56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1265 | HIGH 7.5 | microsoft yammer A security feature bypass vulnerability exists when Microsoft Yammer App for Android fails to apply the correct Intune MAM Policy.This could allow an attacker to perform functions that are restricted by Intune Policy.The security update addresses the vulnerabi | 3.4% | — |
| CVE-2022-21843 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 3.4% | — |
| CVE-2015-1726 | HIGH 7.2 | microsoft windows_7 Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 | 3.4% | — |
| CVE-2022-26832 | HIGH 7.5 | microsoft .net_framework .NET Framework Denial of Service Vulnerability | 3.4% | — |
| CVE-2003-0300 | MED 5.0 | microsoft outlook_express The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors. | 3.4% | — |
| CVE-2019-0683 | MED 5.9 | microsoft windows_7 An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privi | 3.4% | — |
| CVE-2024-38242 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming Service Driver Elevation of Privilege Vulnerability | 3.4% | — |
| CVE-2020-16977 | HIGH 7.0 | microsoft visual_studio_code <p>A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads a Jupyter notebook file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current | 3.4% | — |
| CVE-2024-29996 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 3.4% | — |
| CVE-2020-16862 | HIGH 7.1 | microsoft dynamics_365 <p>A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in | 3.4% | — |
| CVE-2006-2334 | LOW 2.1 | microsoft windows_2000 The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be acce | 3.3% | — |
| CVE-2025-49718 | HIGH 7.5 | microsoft sql_server_2019 Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network. | 3.3% | — |
| CVE-2019-1055 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. | 3.3% | — |
| CVE-2019-1005 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. | 3.3% | — |
| CVE-2021-1721 | MED 6.5 | microsoft .net .NET Core and Visual Studio Denial of Service Vulnerability | 3.3% | — |
| CVE-2017-0165 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Windows Elevation of Privilege Vulnerabilit | 3.3% | — |
| CVE-2015-1723 | HIGH 7.2 | microsoft windows_7 Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 | 3.3% | — |
| CVE-2015-1674 | MED 4.6 | microsoft windows_8 The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate an unspecified address, which allows local users to bypass the KASLR protection mechanism, and consequently discover the cng | 3.3% | — |
| CVE-2001-1347 | MED 4.6 | microsoft windows_2000 Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of | 3.3% | — |
| CVE-2017-11831 | MED 4.7 | microsoft windows_10 Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log on to an affected | 3.3% | — |
| CVE-2022-30150 | HIGH 7.5 | microsoft windows_10 Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability | 3.3% | — |
| CVE-2020-17090 | MED 5.3 | microsoft windows_10 Microsoft Defender for Endpoint Security Feature Bypass Vulnerability | 3.3% | — |
| CVE-2023-36767 | MED 4.3 | microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability | 3.3% | — |
| CVE-2020-16954 | HIGH 7.8 | microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If | 3.3% | — |
| CVE-2020-17123 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 3.3% | — |