IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-1999-1235 MED 4.6 microsoft internet_explorer Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to 2.7%
CVE-2021-33740 HIGH 7.8 microsoft windows_10 Windows Media Remote Code Execution Vulnerability 2.7%
CVE-2020-16969 HIGH 7.1 microsoft exchange_server <p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p> <p>To exploit the 2.7%
CVE-2022-30152 HIGH 7.5 microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2.7%
CVE-2015-1643 HIGH 7.2 microsoft windows_7 Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local user 2.7%
CVE-2018-8564 MED 4.3 microsoft edge A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. 2.7%
CVE-2007-1215 HIGH 7.2 microsoft windows_2000 Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images. 2.7%
CVE-2013-3887 MED 4.9 microsoft windows_7 The Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows local users to obtai 2.7%
CVE-2023-28311 HIGH 7.8 microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability 2.7%
CVE-2024-21438 HIGH 7.5 microsoft windows_10_1507 Microsoft AllJoyn API Denial of Service Vulnerability 2.7%
CVE-2022-21957 HIGH 7.2 microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability 2.7%
CVE-2016-3230 MED 5.0 microsoft windows_10 The Search component in Microsoft Windows 7, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to cause a denial of service (performance degradation) via a crafted applicat 2.7%
CVE-2021-41332 MED 6.5 microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability 2.7%
CVE-2018-8518 MED 5.4 microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft 2.7%
CVE-2001-0919 MED 5.1 microsoft internet_explorer Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript. 2.7%
CVE-2021-43215 CRIT 9.8 microsoft windows_10 iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution 2.7%
CVE-2021-41365 HIGH 8.8 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 2.7%
CVE-2016-7295 MED 5.5 microsoft windows_10 The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local user 2.7%
CVE-2016-7258 MED 5.5 microsoft windows_10 The kernel in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 mishandles page-fault system calls, which allows local users to obtain sensitive information from arbitrary processes via a crafted application, aka "Windows Kernel Memory Address 2.7%
CVE-2021-34449 HIGH 7.0 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 2.7%
CVE-2021-28445 HIGH 8.1 microsoft windows_10 Windows Network File System Remote Code Execution Vulnerability 2.7%
CVE-2000-0167 LOW 2.1 microsoft internet_information_server IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory. 2.7%
CVE-2007-1206 HIGH 7.2 microsoft windows_2000 The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows loca 2.7%
CVE-2021-26876 HIGH 8.8 microsoft windows_10 OpenType Font Parsing Remote Code Execution Vulnerability 2.7%
CVE-2024-21404 HIGH 7.5 microsoft asp.net_core .NET Denial of Service Vulnerability 2.7%