56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.468 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1494 | HIGH 8.8 | microsoft 365_apps A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the | 4.2% | — |
| CVE-2024-20683 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 4.2% | — |
| CVE-2019-0734 | HIGH 8.1 | microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresse | 4.2% | — |
| CVE-2015-2518 | MED 6.9 | microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted appli | 4.2% | — |
| CVE-2015-2511 | MED 6.9 | microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted appli | 4.2% | — |
| CVE-2020-1504 | HIGH 8.8 | microsoft excel A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the | 4.2% | — |
| CVE-2022-21994 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 4.2% | — |
| CVE-2017-11936 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". | 4.2% | — |
| CVE-2010-2744 | HIGH 7.2 | microsoft windows_2003_server The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating | 4.2% | — |
| CVE-2017-8508 | MED 5.5 | microsoft outlook A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of file formats, aka "Microsoft Office Security Feature Bypass Vulnerability". | 4.2% | — |
| CVE-2015-2517 | MED 6.9 | microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted appli | 4.2% | — |
| CVE-2004-0979 | MED 4.6 | microsoft ie Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user's intended configura | 4.2% | — |
| CVE-1999-0372 | LOW 2.1 | microsoft backoffice The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. | 4.2% | — |
| CVE-2024-43629 | HIGH 7.8 | microsoft windows_10_1809 Windows DWM Core Library Elevation of Privilege Vulnerability | 4.2% | — |
| CVE-2020-1558 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.2% | — |
| CVE-2024-38228 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 4.2% | — |
| CVE-2007-5493 | MED 4.3 | microsoft windows_mobile The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded. | 4.2% | — |
| CVE-2021-21136 | MED 6.5 | google chrome Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | 4.2% | — |
| CVE-2025-29809 | HIGH 7.1 | microsoft windows_10_1507 Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally. | 4.2% | — |
| CVE-2020-16950 | MED 5.0 | microsoft sharepoint_server <p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To | 4.2% | — |
| CVE-2017-0249 | HIGH 7.3 | microsoft asp.net_model_view_controller An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | 4.2% | — |
| CVE-2022-21848 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 4.2% | — |
| CVE-2021-30616 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30616 Use after free in Media | 4.2% | — |
| CVE-2021-30609 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30609 Use after free in Sign-In | 4.2% | — |
| CVE-2019-1255 | HIGH 7.5 | microsoft forefront_endpoint_protection_2010 A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'. | 4.1% | — |