56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.463 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26163 | MED 4.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 2.1% | — |
| CVE-2022-35800 | MED 4.9 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2022-35787 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2022-21991 | HIGH 8.1 | microsoft visual_studio_code Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2001-0016 | HIGH 7.2 | microsoft windows_nt NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access. | 2.1% | — |
| CVE-2024-38028 | HIGH 7.2 | microsoft windows_10_1507 Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2024-38025 | HIGH 7.2 | microsoft windows_10_1507 Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2019-0557 | MED 5.4 | microsoft sharepoint_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi | 2.1% | — |
| CVE-2008-2159 | LOW 2.1 | microsoft internet_explorer Microsoft Internet Explorer 7 can save encrypted pages in the cache even when the DisableCachingOfSSLPages registry setting is enabled, which might allow local users to obtain sensitive information. | 2.1% | — |
| CVE-2020-17054 | MED 4.2 | microsoft chakracore Chakra Scripting Engine Memory Corruption Vulnerability | 2.1% | — |
| CVE-2020-1180 | MED 4.2 | microsoft chakracore <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An | 2.1% | — |
| CVE-2005-0550 | LOW 2.1 | microsoft windows_2000 Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability". | 2.1% | — |
| CVE-2023-36912 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.1% | — |
| CVE-2023-36894 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability | 2.1% | — |
| CVE-2019-0837 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'. | 2.1% | — |
| CVE-2023-36909 | MED 6.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.1% | — |
| CVE-2021-43256 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-43234 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-43232 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-41360 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2019-1293 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode driver fails to properly handle objects in memory, aka 'Windows SMB Client Driver Information Disclosure Vulnerability'. | 2.1% | — |
| CVE-2019-0661 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0621, CVE-2019-0663. | 2.1% | — |
| CVE-2019-0628 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | 2.1% | — |
| CVE-2019-0621 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0661, CVE-2019-0663. | 2.1% | — |
| CVE-2020-1057 | MED 4.2 | microsoft chakracore <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An | 2.1% | — |