IT
56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.468 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-1106 MED 6.1 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra 4.0%
CVE-2005-2143 MED 5.0 microsoft frontpage Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page. 4.0%
CVE-2015-2370 HIGH 7.2 microsoft windows_2003_server The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 d 4.0%
CVE-2020-1069 HIGH 8.8 microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls. An authenticated attacker who successfully exploited the vulnerability could use a specially crafted page to 4.0%
CVE-2015-6098 HIGH 7.2 microsoft windows_7 Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows NDIS Elevation of 4.0%
CVE-2018-8410 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve 4.0%
CVE-2017-11874 LOW 3.1 microsoft chakracore Microsoft Edge in Microsoft Windows 10 1703, 1709, Windows Server, version 1709, and ChakraCore allows an attacker to bypass Control Flow Guard (CFG) to run arbitrary code on a target system, due to how Microsoft Edge handles accessing memory in code compiled 4.0%
CVE-2020-16873 MED 4.7 microsoft xamarin.forms <p>A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106. This vulnerability could allow an attacker to execute arbitrary Javascript code on a target system.</p> <p>For the a 4.0%
CVE-2021-30623 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30623 Use after free in Bookmarks 4.0%
CVE-2017-8664 HIGH 8.8 microsoft windows_10 Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from a privileged user on a gu 4.0%
CVE-2017-8591 HIGH 7.8 microsoft windows_10 Windows Input Method Editor (IME) in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an remote code execution vulnerability when it fails to properly handle objects in memory, 4.0%
CVE-2019-1205 CRIT 9.8 microsoft office A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context o 4.0%
CVE-2019-0736 CRIT 9.8 microsoft windows_10 A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. To exploit the vul 4.0%
CVE-2025-59199 HIGH 7.8 microsoft windows_10_1809 Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally. 4.0%
CVE-2020-1117 HIGH 8.8 microsoft windows_10 A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install 4.0%
CVE-2020-1355 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles memory.An attacker who successfully exploited the vulnerability would gain execution on a victim system.The security update addresses the vulnerability by correct 4.0%
CVE-2024-20700 HIGH 7.5 microsoft windows_10_1809 Windows Hyper-V Remote Code Execution Vulnerability 4.0%
CVE-2021-27082 HIGH 7.8 microsoft quantum_development_kit Quantum Development Kit for Visual Studio Code Remote Code Execution Vulnerability 3.9%
CVE-2023-29361 HIGH 7.0 microsoft windows_10_21h2 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 3.9%
CVE-2000-0155 HIGH 7.2 microsoft windows_95 Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive. 3.9%
CVE-1999-1455 HIGH 7.5 microsoft windows_nt RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized h 3.9%
CVE-1999-1316 HIGH 7.5 microsoft windows_nt Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess. 3.9%
CVE-1999-1359 HIGH 7.5 microsoft windows_nt When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies. 3.9%
CVE-2021-26416 HIGH 7.7 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 3.9%
CVE-2015-2508 HIGH 7.2 microsoft windows_10 The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of Privilege Vulnerability." 3.9%