IT
56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.453 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2023-44487 HIGH 7.5 akka http_server The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. 100.0%
CVE-2021-34473 CRIT 9.1 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 100.0%
CVE-2021-26855 CRIT 9.1 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 100.0%
CVE-2019-0708 CRIT 9.8 ransomware huawei agile_controller-campus_firmware A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code 100.0%
CVE-2015-1635 CRIT 9.8 microsoft windows_7 HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability." 100.0%
CVE-2023-50387 HIGH 7.5 fedoraproject fedora Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when ther 100.0%
CVE-2021-34523 CRIT 9.0 ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 100.0%
CVE-2025-53770 CRIT 9.8 ransomware microsoft sharepoint_server Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a co 100.0%
CVE-2022-41082 HIGH 8.0 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 100.0%
CVE-2012-0158 HIGH 8.8 microsoft biztalk_server The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2 100.0%
CVE-2020-0688 HIGH 8.8 ransomware microsoft exchange_server A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'. 100.0%
CVE-2022-41040 HIGH 8.8 ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 100.0%
CVE-2021-27065 HIGH 7.8 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 99.9%
CVE-2017-11882 HIGH 7.8 ransomware microsoft office Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memo 99.9%
CVE-2025-59287 CRIT 9.8 microsoft windows_server_2012 Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. 99.9%
CVE-2021-38647 CRIT 9.8 ransomware microsoft azure_automation_state_configuration Open Management Infrastructure (OMI) Remote Code Execution Vulnerability 99.9%
CVE-2017-0199 HIGH 7.8 ransomware microsoft office Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, ak 99.9%
CVE-2025-49704 HIGH 8.8 ransomware microsoft sharepoint_server Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 99.9%
CVE-2025-53771 MED 6.5 microsoft sharepoint_server Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 99.9%
CVE-2025-49706 MED 6.5 ransomware microsoft sharepoint_enterprise_server Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 99.9%
CVE-2015-4000 LOW 3.7 apple iphone_os The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello wi 99.9%
CVE-2019-0604 CRIT 9.8 ransomware microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594. 99.8%
CVE-2017-7269 CRIT 9.8 microsoft internet_information_services Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PRO 99.8%
CVE-2012-1459 MED 4.3 ahnlab v3_internet_security The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, 99.8%
CVE-2020-0796 CRIT 10.0 ransomware microsoft windows_10_1903 A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. 99.8%