IT
58.493 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.469 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2009-1537 HIGH 8.8 microsoft directx Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a cr 51.2%
CVE-2015-2502 HIGH 8.8 microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015. 51.0%
CVE-2024-38094 HIGH 7.2 ransomware microsoft sharepoint_server Microsoft SharePoint Remote Code Execution Vulnerability 50.9%
CVE-2013-7331 MED 6.5 microsoft internet_explorer The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a r 50.2%
CVE-2011-1889 CRIT 9.8 microsoft forefront_threat_management_gateway The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability." 49.0%
CVE-2023-5217 HIGH 8.8 apple ipados Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 49.0%
CVE-2015-1671 HIGH 7.8 microsoft .net_framework The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 49.0%
CVE-2023-28252 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 49.0%
CVE-2020-16009 HIGH 8.8 cefsharp cefsharp Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. 48.3%
CVE-2006-2492 HIGH 8.8 microsoft office Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 200 48.1%
CVE-2014-4123 HIGH 8.8 microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124. 47.1%
CVE-2024-43573 MED 6.5 microsoft windows_10_1507 Windows MSHTML Platform Spoofing Vulnerability 46.1%
CVE-2019-0803 HIGH 7.8 ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859. 45.0%
CVE-2024-29988 HIGH 8.8 microsoft windows_10_1809 SmartScreen Prompt Security Feature Bypass Vulnerability 44.9%
CVE-2015-2425 HIGH 8.8 microsoft internet_explorer Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2383 and 44.7%
CVE-2013-3900 MED 5.5 microsoft windows_10_1507 Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windo 44.6%
CVE-2016-3235 HIGH 7.8 microsoft visio Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vuln 43.3%
CVE-2007-0671 HIGH 8.8 microsoft access Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero 43.2%
CVE-2009-0238 HIGH 8.8 microsoft excel Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attacker 43.2%
CVE-2021-42292 HIGH 7.8 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 43.0%
CVE-2023-36874 HIGH 7.8 microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability 42.6%
CVE-2020-0787 HIGH 7.8 ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'. 42.5%
CVE-2019-0841 HIGH 7.8 ransomware microsoft windows_10_1703 An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-08 41.4%
CVE-2024-38178 HIGH 7.5 microsoft windows_10_1507 Scripting Engine Memory Corruption Vulnerability 41.4%
CVE-2023-4762 HIGH 8.8 debian debian_linux Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) 41.4%