IT
56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-0557 MED 5.4 microsoft sharepoint_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi 2.1%
CVE-2008-2159 LOW 2.1 microsoft internet_explorer Microsoft Internet Explorer 7 can save encrypted pages in the cache even when the DisableCachingOfSSLPages registry setting is enabled, which might allow local users to obtain sensitive information. 2.1%
CVE-2020-17054 MED 4.2 microsoft chakracore Chakra Scripting Engine Memory Corruption Vulnerability 2.1%
CVE-2020-1180 MED 4.2 microsoft chakracore <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An 2.1%
CVE-2005-0550 LOW 2.1 microsoft windows_2000 Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability". 2.1%
CVE-2023-36912 HIGH 7.5 microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.1%
CVE-2023-36894 MED 6.5 microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability 2.1%
CVE-2019-0837 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'. 2.1%
CVE-2023-36909 MED 6.5 microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.1%
CVE-2021-43256 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2.1%
CVE-2021-43234 HIGH 7.8 microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability 2.1%
CVE-2021-43232 HIGH 7.8 microsoft windows_10 Windows Event Tracing Remote Code Execution Vulnerability 2.1%
CVE-2021-41360 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.1%
CVE-2019-1293 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode driver fails to properly handle objects in memory, aka 'Windows SMB Client Driver Information Disclosure Vulnerability'. 2.1%
CVE-2019-0661 MED 5.5 microsoft windows_7 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0621, CVE-2019-0663. 2.1%
CVE-2019-0628 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. 2.1%
CVE-2019-0621 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0661, CVE-2019-0663. 2.1%
CVE-2020-1057 MED 4.2 microsoft chakracore <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An 2.1%
CVE-2025-55232 CRIT 9.8 microsoft hpc_pack Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. 2.1%
CVE-2020-1059 MED 4.3 microsoft edge A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could e 2.1%
CVE-2025-62204 HIGH 8.0 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2.1%
CVE-2023-33148 HIGH 7.8 microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability 2.1%
CVE-2020-17153 MED 4.3 microsoft edge Microsoft Edge for Android Spoofing Vulnerability 2.1%
CVE-2017-0043 MED 5.3 microsoft windows_10 Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Microsoft Active 2.1%
CVE-2019-0838 HIGH 7.8 microsoft windows_10 An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839. 2.1%