56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-1235 | MED 4.6 | microsoft internet_explorer Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to | 2.7% | — |
| CVE-2021-33740 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-16969 | HIGH 7.1 | microsoft exchange_server <p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p> <p>To exploit the | 2.7% | — |
| CVE-2022-30152 | HIGH 7.5 | microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.7% | — |
| CVE-2015-1643 | HIGH 7.2 | microsoft windows_7 Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local user | 2.7% | — |
| CVE-2018-8564 | MED 4.3 | microsoft edge A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. | 2.7% | — |
| CVE-2007-1215 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images. | 2.7% | — |
| CVE-2013-3887 | MED 4.9 | microsoft windows_7 The Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows local users to obtai | 2.7% | — |
| CVE-2023-28311 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2024-21438 | HIGH 7.5 | microsoft windows_10_1507 Microsoft AllJoyn API Denial of Service Vulnerability | 2.7% | — |
| CVE-2022-21957 | HIGH 7.2 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2016-3230 | MED 5.0 | microsoft windows_10 The Search component in Microsoft Windows 7, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to cause a denial of service (performance degradation) via a crafted applicat | 2.7% | — |
| CVE-2021-41332 | MED 6.5 | microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability | 2.7% | — |
| CVE-2018-8518 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.7% | — |
| CVE-2001-0919 | MED 5.1 | microsoft internet_explorer Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript. | 2.7% | — |
| CVE-2021-43215 | CRIT 9.8 | microsoft windows_10 iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution | 2.7% | — |
| CVE-2021-41365 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2016-7295 | MED 5.5 | microsoft windows_10 The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local user | 2.7% | — |
| CVE-2016-7258 | MED 5.5 | microsoft windows_10 The kernel in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 mishandles page-fault system calls, which allows local users to obtain sensitive information from arbitrary processes via a crafted application, aka "Windows Kernel Memory Address | 2.7% | — |
| CVE-2021-34449 | HIGH 7.0 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2021-28445 | HIGH 8.1 | microsoft windows_10 Windows Network File System Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2000-0167 | LOW 2.1 | microsoft internet_information_server IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory. | 2.7% | — |
| CVE-2007-1206 | HIGH 7.2 | microsoft windows_2000 The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows loca | 2.7% | — |
| CVE-2021-26876 | HIGH 8.8 | microsoft windows_10 OpenType Font Parsing Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2024-21404 | HIGH 7.5 | microsoft asp.net_core .NET Denial of Service Vulnerability | 2.7% | — |