IT
56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.468 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-35608 HIGH 7.8 microsoft azure_sphere A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with controllable content. An attac 4.0%
CVE-2020-17110 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 4.0%
CVE-2020-17108 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 4.0%
CVE-2020-17107 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 4.0%
CVE-2020-17106 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 4.0%
CVE-2020-1564 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu 4.0%
CVE-2020-1562 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user 4.0%
CVE-2022-35761 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 4.0%
CVE-2021-42311 CRIT 10.0 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 4.0%
CVE-2020-16997 HIGH 7.7 microsoft windows_10 Remote Desktop Protocol Server Information Disclosure Vulnerability 4.0%
CVE-2019-1397 HIGH 8.4 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CV 4.0%
CVE-2019-1389 HIGH 8.4 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CV 4.0%
CVE-2008-4927 MED 4.3 microsoft windows_media_player Microsoft Windows Media Player (WMP) 9.0 through 11 allows user-assisted attackers to cause a denial of service (application crash) via a malformed (1) MIDI or (2) DAT file, related to "MThd Header Parsing." NOTE: the provenance of this information is unknown; 4.0%
CVE-2021-27056 HIGH 7.8 microsoft 365_apps Microsoft PowerPoint Remote Code Execution Vulnerability 4.0%
CVE-2008-3464 HIGH 7.2 microsoft windows_2003_server afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted appli 4.0%
CVE-2021-34494 HIGH 8.8 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 4.0%
CVE-2016-0006 HIGH 7.3 microsoft windows_10 The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows 4.0%
CVE-2020-1126 HIGH 8.8 microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri 4.0%
CVE-2021-36940 HIGH 7.6 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 4.0%
CVE-2001-1515 HIGH 7.5 microsoft windows_2000 Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended. 4.0%
CVE-2015-6095 MED 4.9 microsoft windows_10 Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles password changes, which allows physically prox 4.0%
CVE-2023-36743 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 4.0%
CVE-2020-0664 MED 6.5 microsoft windows_server_2008 <p>An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited this vulnerability would be able to read sensitive information about the target s 4.0%
CVE-2000-0765 MED 5.1 microsoft excel Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability. 4.0%
CVE-2019-1172 MED 4.3 microsoft windows_10 An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an 4.0%