IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.469 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-33825 HIGH 7.8 ransomware microsoft defender_antimalware_platform Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-81963 HIGH 7.8 microsoft windows_11_23h2 Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-56155 HIGH 7.8 microsoft windows_10_1607 Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-68820 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2023-50387 HIGH 7.5 fedoraproject fedora Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when ther 100.0% —
CVE-2015-4000 LOW 3.7 apple iphone_os The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello wi 99.9% —
CVE-2012-1459 MED 4.3 ahnlab v3_internet_security The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, 99.8% —
CVE-2025-53771 MED 6.5 microsoft sharepoint_server Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 99.8% —
CVE-2012-1443 MED 4.3 ahnlab v3_internet_security The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 99.6% —
CVE-2003-0352 HIGH 7.5 microsoft windows_2000 Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms. 98.5% —
CVE-2009-1122 HIGH 7.5 microsoft internet_information_services The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 Web 98.4% —
CVE-2012-1457 MED 4.3 aladdin esafe The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti- 98.3% —
CVE-2009-1535 HIGH 7.5 microsoft internet_information_services The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position 98.1% —
CVE-2012-1453 MED 4.3 antiy avl_sdk The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust V 97.7% —
CVE-2012-1420 MED 4.3 authentium command_antivirus The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essen 97.1% —
CVE-2015-0014 HIGH 10.0 microsoft windows_7 Buffer overflow in the Telnet service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via 96.9% —
CVE-2001-0500 HIGH 10.0 microsoft index_server Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.id 96.7% —
CVE-2014-6321 HIGH 10.0 microsoft windows_7 Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via craf 96.0% —
CVE-1999-0016 MED 5.0 cisco ios Land IP denial of service. 95.7% —
CVE-2023-21554 CRIT 9.8 microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 95.5% —
CVE-2023-24941 CRIT 9.8 microsoft windows_server_2012 Windows Network File System Remote Code Execution Vulnerability 94.7% —
CVE-2013-3182 HIGH 7.8 microsoft windows_server_2012 The Windows NAT Driver (aka winnat) service in Microsoft Windows Server 2012 does not properly validate memory addresses during the processing of ICMP packets, which allows remote attackers to cause a denial of service (memory corruption and system hang) via c 94.6% —
CVE-2010-3972 HIGH 10.0 microsoft internet_information_services Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute arbitrary code or cause a denial of ser 94.5% —
CVE-2010-3964 HIGH 7.5 microsoft sharepoint_server Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted 94.2% —
CVE-2021-41349 MED 6.5 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 93.5% —