56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.468 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-35608 | HIGH 7.8 | microsoft azure_sphere A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with controllable content. An attac | 4.0% | — |
| CVE-2020-17110 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 4.0% | — |
| CVE-2020-17108 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 4.0% | — |
| CVE-2020-17107 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 4.0% | — |
| CVE-2020-17106 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 4.0% | — |
| CVE-2020-1564 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.0% | — |
| CVE-2020-1562 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user | 4.0% | — |
| CVE-2022-35761 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 4.0% | — |
| CVE-2021-42311 | CRIT 10.0 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 4.0% | — |
| CVE-2020-16997 | HIGH 7.7 | microsoft windows_10 Remote Desktop Protocol Server Information Disclosure Vulnerability | 4.0% | — |
| CVE-2019-1397 | HIGH 8.4 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CV | 4.0% | — |
| CVE-2019-1389 | HIGH 8.4 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CV | 4.0% | — |
| CVE-2008-4927 | MED 4.3 | microsoft windows_media_player Microsoft Windows Media Player (WMP) 9.0 through 11 allows user-assisted attackers to cause a denial of service (application crash) via a malformed (1) MIDI or (2) DAT file, related to "MThd Header Parsing." NOTE: the provenance of this information is unknown; | 4.0% | — |
| CVE-2021-27056 | HIGH 7.8 | microsoft 365_apps Microsoft PowerPoint Remote Code Execution Vulnerability | 4.0% | — |
| CVE-2008-3464 | HIGH 7.2 | microsoft windows_2003_server afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted appli | 4.0% | — |
| CVE-2021-34494 | HIGH 8.8 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 4.0% | — |
| CVE-2016-0006 | HIGH 7.3 | microsoft windows_10 The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows | 4.0% | — |
| CVE-2020-1126 | HIGH 8.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 4.0% | — |
| CVE-2021-36940 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 4.0% | — |
| CVE-2001-1515 | HIGH 7.5 | microsoft windows_2000 Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended. | 4.0% | — |
| CVE-2015-6095 | MED 4.9 | microsoft windows_10 Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles password changes, which allows physically prox | 4.0% | — |
| CVE-2023-36743 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 4.0% | — |
| CVE-2020-0664 | MED 6.5 | microsoft windows_server_2008 <p>An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited this vulnerability would be able to read sensitive information about the target s | 4.0% | — |
| CVE-2000-0765 | MED 5.1 | microsoft excel Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability. | 4.0% | — |
| CVE-2019-1172 | MED 4.3 | microsoft windows_10 An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an | 4.0% | — |