IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.469 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1009 MED 4.7 microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are 48.5% —
CVE-2002-0648 MED 5.0 microsoft internet_explorer The legacy <script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file. 48.4% —
CVE-2003-0816 HIGH 7.5 microsoft ie Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL conta 48.4% —
CVE-2010-0028 HIGH 9.3 microsoft windows_2000 Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability." 48.3% —
CVE-2008-0116 HIGH 9.3 microsoft excel Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability." 48.2% —
CVE-2006-3281 MED 5.1 microsoft internet_explorer Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code via a link to an SMB file share with a filename that contains encoded ..\ (%2e%2e%5c) sequences and whose exten 48.2% —
CVE-2021-40487 HIGH 8.1 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 48.2% —
CVE-2010-0270 HIGH 10.0 microsoft windows_7 The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corr 48.2% —
CVE-2017-0141 HIGH 7.5 microsoft edge A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in 48.2% —
CVE-2001-0986 MED 5.0 microsoft index_server SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2 48.2% —
CVE-2008-1547 MED 4.3 microsoft exchange_server Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL para 48.1% —
CVE-2016-7189 HIGH 7.5 microsoft edge The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Remote Code Execution Vulnerability." 48.1% —
CVE-2017-8541 HIGH 7.8 microsoft forefront_security The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a 48.1% —
CVE-2000-1200 MED 5.0 microsoft windows_nt Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users. 48.1% —
CVE-2019-1040 MED 5.3 microsoft windows_10 A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgr 48.0% —
CVE-2006-2766 LOW 2.6 microsoft ie Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mht 47.9% —
CVE-2008-4032 HIGH 7.5 microsoft office_sharepoint_server Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensit 47.9% —
CVE-2006-3654 LOW 2.6 microsoft works Buffer overflow in wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted Excel files. 47.9% —
CVE-2010-4701 HIGH 7.6 microsoft windows_2003_server Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers 47.8% —
CVE-2021-34481 HIGH 8.8 microsoft windows_10 A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the 47.7% —
CVE-2004-0121 HIGH 7.5 microsoft office Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arb 47.7% —
CVE-2005-2118 MED 5.1 microsoft windows_2000 Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views th 47.7% —
CVE-2005-0063 HIGH 7.5 microsoft windows_2000 The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application H 47.6% —
CVE-2025-53778 HIGH 8.8 microsoft windows_10_1507 Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. 47.6% —
CVE-2000-0114 MED 5.0 microsoft internet_information_server Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. 47.6% —