56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.468 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1106 | MED 6.1 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 4.0% | — |
| CVE-2005-2143 | MED 5.0 | microsoft frontpage Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page. | 4.0% | — |
| CVE-2015-2370 | HIGH 7.2 | microsoft windows_2003_server The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 d | 4.0% | — |
| CVE-2020-1069 | HIGH 8.8 | microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls. An authenticated attacker who successfully exploited the vulnerability could use a specially crafted page to | 4.0% | — |
| CVE-2015-6098 | HIGH 7.2 | microsoft windows_7 Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows NDIS Elevation of | 4.0% | — |
| CVE-2018-8410 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve | 4.0% | — |
| CVE-2017-11874 | LOW 3.1 | microsoft chakracore Microsoft Edge in Microsoft Windows 10 1703, 1709, Windows Server, version 1709, and ChakraCore allows an attacker to bypass Control Flow Guard (CFG) to run arbitrary code on a target system, due to how Microsoft Edge handles accessing memory in code compiled | 4.0% | — |
| CVE-2020-16873 | MED 4.7 | microsoft xamarin.forms <p>A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106. This vulnerability could allow an attacker to execute arbitrary Javascript code on a target system.</p> <p>For the a | 4.0% | — |
| CVE-2021-30623 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30623 Use after free in Bookmarks | 4.0% | — |
| CVE-2017-8664 | HIGH 8.8 | microsoft windows_10 Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from a privileged user on a gu | 4.0% | — |
| CVE-2017-8591 | HIGH 7.8 | microsoft windows_10 Windows Input Method Editor (IME) in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an remote code execution vulnerability when it fails to properly handle objects in memory, | 4.0% | — |
| CVE-2019-1205 | CRIT 9.8 | microsoft office A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context o | 4.0% | — |
| CVE-2019-0736 | CRIT 9.8 | microsoft windows_10 A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. To exploit the vul | 4.0% | — |
| CVE-2025-59199 | HIGH 7.8 | microsoft windows_10_1809 Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally. | 4.0% | — |
| CVE-2020-1117 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install | 4.0% | — |
| CVE-2020-1355 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles memory.An attacker who successfully exploited the vulnerability would gain execution on a victim system.The security update addresses the vulnerability by correct | 4.0% | — |
| CVE-2024-20700 | HIGH 7.5 | microsoft windows_10_1809 Windows Hyper-V Remote Code Execution Vulnerability | 4.0% | — |
| CVE-2021-27082 | HIGH 7.8 | microsoft quantum_development_kit Quantum Development Kit for Visual Studio Code Remote Code Execution Vulnerability | 3.9% | — |
| CVE-2023-29361 | HIGH 7.0 | microsoft windows_10_21h2 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 3.9% | — |
| CVE-2000-0155 | HIGH 7.2 | microsoft windows_95 Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive. | 3.9% | — |
| CVE-1999-1455 | HIGH 7.5 | microsoft windows_nt RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized h | 3.9% | — |
| CVE-1999-1316 | HIGH 7.5 | microsoft windows_nt Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess. | 3.9% | — |
| CVE-1999-1359 | HIGH 7.5 | microsoft windows_nt When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies. | 3.9% | — |
| CVE-2021-26416 | HIGH 7.7 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 3.9% | — |
| CVE-2015-2508 | HIGH 7.2 | microsoft windows_10 The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of Privilege Vulnerability." | 3.9% | — |