56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.468 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-7224 | MED 6.1 | microsoft windows_10 Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted a | 4.1% | — |
| CVE-2015-6102 | LOW 2.1 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mecha | 4.1% | — |
| CVE-2013-2554 | HIGH 7.5 | microsoft windows_7 Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR and DEP protection mechanisms via unknown vectors, as demonstrated against Firefox by VUPEN during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE | 4.1% | — |
| CVE-2021-43208 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 4.1% | — |
| CVE-2021-28471 | HIGH 7.8 | microsoft visual_studio_code Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability | 4.1% | — |
| CVE-2018-0746 | MED 4.7 | microsoft windows_10 The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handle | 4.1% | — |
| CVE-2019-0974 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.1% | — |
| CVE-2019-0907 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.1% | — |
| CVE-2019-0905 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.1% | — |
| CVE-2019-0904 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.1% | — |
| CVE-2021-30622 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30622 Use after free in WebApp Installs | 4.1% | — |
| CVE-2021-30608 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30608 Use after free in Web Share | 4.1% | — |
| CVE-2021-27095 | HIGH 7.8 | microsoft windows_10 Windows Media Video Decoder Remote Code Execution Vulnerability | 4.1% | — |
| CVE-2021-28453 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 4.1% | — |
| CVE-2009-0079 | MED 6.9 | microsoft windows_server_2003 The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which all | 4.1% | — |
| CVE-2021-27057 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 4.1% | — |
| CVE-2021-27054 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 4.1% | — |
| CVE-2017-0171 | MED 5.9 | microsoft windows_server_2008 Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 are configured to answer version queries, aka "Windows DNS Server Denial of Service Vulnerab | 4.1% | — |
| CVE-2025-54110 | HIGH 8.8 | microsoft windows_10_1507 Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. | 4.1% | — |
| CVE-2023-21706 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 4.1% | — |
| CVE-2017-8724 | MED 4.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 Version 1703 allows an attacker to trick a user by redirecting the user to a specially crafted website, due to the way that Microsoft Edge parses HTTP content, aka "Microsoft Edge Spoofing Vulnerability". This CVE ID is u | 4.0% | — |
| CVE-2023-23408 | MED 4.5 | microsoft azure_hdinsight Azure Apache Ambari Spoofing Vulnerability | 4.0% | — |
| CVE-2022-22012 | CRIT 9.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 4.0% | — |
| CVE-2019-0709 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a | 4.0% | — |
| CVE-2003-0306 | HIGH 7.2 | microsoft windows_xp Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter. | 4.0% | — |