56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36560 | HIGH 8.8 | microsoft .net_framework ASP.NET Security Feature Bypass Vulnerability | 2.9% | — |
| CVE-2018-8156 | MED 5.4 | microsoft project_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.9% | — |
| CVE-2018-8155 | MED 5.4 | microsoft sharepoint_foundation An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.9% | — |
| CVE-2018-8149 | MED 5.4 | microsoft sharepoint_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.9% | — |
| CVE-2021-31205 | MED 6.5 | microsoft windows_10 Windows SMB Client Security Feature Bypass Vulnerability | 2.9% | — |
| CVE-2020-17082 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2022-21925 | MED 5.3 | microsoft windows_7 Windows BackupKey Remote Protocol Security Feature Bypass Vulnerability | 2.9% | — |
| CVE-2022-21924 | MED 5.3 | microsoft windows_10 Workstation Service Remote Protocol Security Feature Bypass Vulnerability | 2.9% | — |
| CVE-2022-22021 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2024-20672 | HIGH 7.5 | microsoft .net .NET Denial of Service Vulnerability | 2.9% | — |
| CVE-2022-21877 | MED 5.5 | microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability | 2.9% | — |
| CVE-2021-38669 | MED 6.4 | microsoft edge Microsoft Edge (Chromium-based) Tampering Vulnerability | 2.9% | — |
| CVE-2024-21319 | MED 6.8 | microsoft .net Microsoft Identity Denial of service vulnerability | 2.9% | — |
| CVE-2021-26439 | MED 4.6 | microsoft edge Microsoft Edge for Android Information Disclosure Vulnerability | 2.9% | — |
| CVE-1999-0700 | MED 6.2 | microsoft windows_2000 Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. | 2.9% | — |
| CVE-2021-24099 | MED 6.5 | microsoft lync_server Skype for Business and Lync Denial of Service Vulnerability | 2.9% | — |
| CVE-2014-5239 | MED 4.0 | microsoft outlook.com The Microsoft Outlook.com application before 7.8.2.12.49.7090 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2.9% | — |
| CVE-2021-42295 | MED 5.5 | microsoft 365_apps Visual Basic for Applications Information Disclosure Vulnerability | 2.9% | — |
| CVE-2018-8306 | MED 5.5 | microsoft wireless_display_adapter_firmware A command injection vulnerability exists in the Microsoft Wireless Display Adapter (MWDA) when the Microsoft Wireless Display Adapter does not properly manage user input, aka "Microsoft Wireless Display Adapter Command Injection Vulnerability." This affects Mi | 2.9% | — |
| CVE-2006-5586 | HIGH 7.2 | microsoft windows_2000 The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability." | 2.9% | — |
| CVE-2014-4115 | HIGH 7.2 | microsoft windows_server_2003 fastfat.sys (aka the FASTFAT driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly allocate memory, which allows physically proximate attackers to execute arbitrary code or cause a denial of s | 2.9% | — |
| CVE-2020-17156 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2018-8112 | MED 4.3 | microsoft edge A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge. | 2.9% | — |
| CVE-2019-1364 | HIGH 7.8 | microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1362. | 2.9% | — |
| CVE-2024-43483 | HIGH 7.5 | microsoft .net .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | 2.9% | — |