58.465 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.464 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-44487 | HIGH 7.5 | akka http_server The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | 100.0% | |
| CVE-2015-1635 | CRIT 9.8 | microsoft windows_7 HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability." | 100.0% | |
| CVE-2021-34473 | CRIT 9.1 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 100.0% | |
| CVE-2019-0708 | CRIT 9.8 | ransomware huawei agile_controller-campus_firmware A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code | 100.0% | |
| CVE-2025-53770 | CRIT 9.8 | ransomware microsoft sharepoint_server Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a co | 100.0% | |
| CVE-2021-26855 | CRIT 9.1 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 100.0% | |
| CVE-2025-49704 | HIGH 8.8 | ransomware microsoft sharepoint_server Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 100.0% | |
| CVE-2021-34523 | CRIT 9.0 | ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 100.0% | |
| CVE-2023-29357 | CRIT 9.8 | ransomware microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability | 100.0% | |
| CVE-2025-59287 | CRIT 9.8 | microsoft windows_server_2012 Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | 100.0% | |
| CVE-2023-4863 | HIGH 8.8 | bandisoft honeyview Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) | 100.0% | |
| CVE-2012-0158 | HIGH 8.8 | ransomware microsoft biztalk_server The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2 | 100.0% | |
| CVE-2022-41082 | HIGH 8.0 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 100.0% | |
| CVE-2020-0688 | HIGH 8.8 | ransomware microsoft exchange_server A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'. | 100.0% | |
| CVE-2022-41040 | HIGH 8.8 | ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 100.0% | |
| CVE-2017-11882 | HIGH 7.8 | ransomware microsoft office Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memo | 99.9% | |
| CVE-2021-38647 | CRIT 9.8 | ransomware microsoft azure_automation_state_configuration Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | 99.9% | |
| CVE-2019-0604 | CRIT 9.8 | ransomware microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594. | 99.9% | |
| CVE-2021-27065 | HIGH 7.8 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 99.9% | |
| CVE-2021-31166 | CRIT 9.8 | microsoft windows_10_2004 HTTP Protocol Stack Remote Code Execution Vulnerability | 99.9% | |
| CVE-2017-7269 | CRIT 9.8 | microsoft internet_information_services Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PRO | 99.8% | |
| CVE-2020-0796 | CRIT 10.0 | ransomware microsoft windows_10_1903 A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. | 99.8% | |
| CVE-2021-34527 | HIGH 8.8 | ransomware microsoft windows_10_1507 A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the | 99.8% | |
| CVE-2021-31207 | MED 6.6 | ransomware microsoft exchange_server Microsoft Exchange Server Security Feature Bypass Vulnerability | 99.8% | |
| CVE-2017-0147 | HIGH 7.5 | ransomware microsoft windows_10_1507 The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sen | 99.7% |