56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-6947 | HIGH 7.8 | microsoft windows_10 An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of se | 3.1% | — |
| CVE-2020-17058 | HIGH 7.5 | microsoft edge Microsoft Browser Memory Corruption Vulnerability | 3.1% | — |
| CVE-2017-0233 | HIGH 8.3 | microsoft edge An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0241. | 3.1% | — |
| CVE-2024-21322 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2021-31177 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2019-1057 | HIGH 7.5 | microsoft windows_10 A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system. To exploit the | 3.1% | — |
| CVE-2018-8411 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, W | 3.1% | — |
| CVE-2019-1344 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memory, aka 'Windows Code Integrity Module Information Disclosure Vulnerability'. | 3.1% | — |
| CVE-2001-1560 | LOW 2.1 | microsoft windows_2000 Win32k.sys (aka Graphics Device Interface (GDI)) in Windows 2000 and XP allows local users to cause a denial of service (system crash) by calling the ShowWindow function after receiving a WM_NCCREATE message. | 3.1% | — |
| CVE-2024-21392 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 3.1% | — |
| CVE-2021-36970 | HIGH 8.8 | microsoft windows_10 Windows Print Spooler Spoofing Vulnerability | 3.1% | — |
| CVE-2021-26868 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 3.1% | — |
| CVE-2019-1193 | MED 6.4 | microsoft edge A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who | 3.1% | — |
| CVE-2024-43485 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 3.1% | — |
| CVE-2022-21911 | HIGH 7.5 | microsoft .net_framework .NET Framework Denial of Service Vulnerability | 3.1% | — |
| CVE-2015-1680 | LOW 2.1 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protec | 3.1% | — |
| CVE-2015-1679 | LOW 2.1 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protec | 3.1% | — |
| CVE-2015-1678 | LOW 2.1 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protec | 3.1% | — |
| CVE-2015-1677 | LOW 2.1 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protec | 3.1% | — |
| CVE-2015-1676 | LOW 2.1 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR protec | 3.1% | — |
| CVE-2023-24860 | HIGH 7.5 | microsoft malware_protection_engine Microsoft Defender Denial of Service Vulnerability | 3.0% | — |
| CVE-2021-31176 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2022-21996 | HIGH 7.8 | microsoft windows_11 Win32k Elevation of Privilege Vulnerability | 3.0% | — |
| CVE-2018-8134 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, W | 3.0% | — |
| CVE-2022-26831 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | 3.0% | — |