56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-16934 | HIGH 7.0 | microsoft 365_apps <p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges.</p> <p>To exploit this vulnerability, an atta | 2.7% | — |
| CVE-2020-1582 | HIGH 7.8 | microsoft 365_apps A remote code execution vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the | 2.7% | — |
| CVE-2020-1534 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafte | 2.7% | — |
| CVE-2020-1531 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Accounts Control improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted appli | 2.7% | — |
| CVE-2020-1478 | HIGH 7.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 2.7% | — |
| CVE-2020-1345 | HIGH 7.4 | microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially | 2.7% | — |
| CVE-2022-37966 | HIGH 8.1 | fedoraproject fedora Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2022-29141 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2018-8254 | MED 5.4 | microsoft project_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.7% | — |
| CVE-2018-8252 | MED 5.4 | microsoft sharepoint_foundation An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.7% | — |
| CVE-2024-26215 | HIGH 7.5 | microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability | 2.7% | — |
| CVE-2021-38629 | MED 6.5 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability | 2.7% | — |
| CVE-2020-1198 | HIGH 7.4 | microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially | 2.7% | — |
| CVE-2021-42309 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2015-0095 | MED 5.6 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to cause a denial of serv | 2.7% | — |
| CVE-2022-21878 | HIGH 7.8 | microsoft windows_10 Windows Geolocation Service Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2023-36034 | HIGH 7.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-31958 | HIGH 7.5 | microsoft windows_10 Windows NTLM Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2022-29109 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2010-1734 | MED 4.9 | microsoft windows_2000 The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call fo | 2.7% | — |
| CVE-2024-38126 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.7% | — |
| CVE-2023-36010 | HIGH 7.5 | microsoft malware_protection_platform Microsoft Defender Denial of Service Vulnerability | 2.7% | — |
| CVE-2022-30133 | CRIT 9.8 | microsoft windows_10 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-17052 | HIGH 7.5 | microsoft edge Scripting Engine Memory Corruption Vulnerability | 2.7% | — |
| CVE-2015-0010 | LOW 1.9 | microsoft windows_7 The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Serv | 2.6% | — |