56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-26919 | HIGH 8.1 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-31200 | HIGH 7.2 | microsoft neural_network_intelligence Common Utilities Remote Code Execution Vulnerability | 2.5% | — |
| CVE-1999-0595 | LOW 2.1 | microsoft windows_2000 A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded. | 2.5% | — |
| CVE-2024-38073 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Denial of Service Vulnerability | 2.5% | — |
| CVE-2000-0487 | LOW 3.6 | microsoft windows_2000 The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability. | 2.5% | — |
| CVE-2020-17115 | HIGH 8.0 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 2.5% | — |
| CVE-2022-21980 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 2.5% | — |
| CVE-2019-0993 | MED 4.2 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 2.5% | — |
| CVE-2019-0991 | MED 4.2 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 2.5% | — |
| CVE-2017-11876 | HIGH 8.8 | microsoft project_server Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on behalf of the victim, | 2.5% | — |
| CVE-2022-30171 | MED 5.5 | microsoft office_online_server Microsoft Office Information Disclosure Vulnerability | 2.5% | — |
| CVE-2021-28449 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2023-35368 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-40465 | HIGH 7.8 | microsoft windows_10 Windows Text Shaping Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2020-16857 | HIGH 7.1 | microsoft dynamics_365_for_finance_and_operations <p>A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gain remote code execution via server-side script execution on t | 2.5% | — |
| CVE-2023-35385 | CRIT 9.8 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2024-35252 | HIGH 7.5 | microsoft azure_storage_data_movement_library Azure Storage Movement Client Library Denial of Service Vulnerability | 2.5% | — |
| CVE-2021-24082 | MED 4.3 | microsoft windows_10 Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability | 2.5% | — |
| CVE-2023-38157 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 2.5% | — |
| CVE-2020-1173 | MED 6.8 | microsoft power_bi_report_server A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially crafted payload and sending it to the user. | 2.5% | — |
| CVE-2019-0950 | MED 5.7 | microsoft sharepoint_foundation A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019- | 2.5% | — |
| CVE-2019-0949 | MED 5.7 | microsoft sharepoint_foundation A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950, CVE-2019- | 2.5% | — |
| CVE-1999-0585 | LOW 2.1 | microsoft windows_2000 A Windows NT administrator account has the default name of Administrator. | 2.5% | — |
| CVE-2022-30188 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-30179 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 2.5% | — |