56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-0557 | MED 5.4 | microsoft sharepoint_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi | 2.1% | — |
| CVE-2008-2159 | LOW 2.1 | microsoft internet_explorer Microsoft Internet Explorer 7 can save encrypted pages in the cache even when the DisableCachingOfSSLPages registry setting is enabled, which might allow local users to obtain sensitive information. | 2.1% | — |
| CVE-2020-17054 | MED 4.2 | microsoft chakracore Chakra Scripting Engine Memory Corruption Vulnerability | 2.1% | — |
| CVE-2020-1180 | MED 4.2 | microsoft chakracore <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An | 2.1% | — |
| CVE-2005-0550 | LOW 2.1 | microsoft windows_2000 Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability". | 2.1% | — |
| CVE-2023-36912 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.1% | — |
| CVE-2023-36894 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability | 2.1% | — |
| CVE-2019-0837 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'. | 2.1% | — |
| CVE-2023-36909 | MED 6.5 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.1% | — |
| CVE-2021-43256 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-43234 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-43232 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-41360 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2019-1293 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode driver fails to properly handle objects in memory, aka 'Windows SMB Client Driver Information Disclosure Vulnerability'. | 2.1% | — |
| CVE-2019-0661 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0621, CVE-2019-0663. | 2.1% | — |
| CVE-2019-0628 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | 2.1% | — |
| CVE-2019-0621 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0661, CVE-2019-0663. | 2.1% | — |
| CVE-2020-1057 | MED 4.2 | microsoft chakracore <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An | 2.1% | — |
| CVE-2025-55232 | CRIT 9.8 | microsoft hpc_pack Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. | 2.1% | — |
| CVE-2020-1059 | MED 4.3 | microsoft edge A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could e | 2.1% | — |
| CVE-2025-62204 | HIGH 8.0 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.1% | — |
| CVE-2023-33148 | HIGH 7.8 | microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2020-17153 | MED 4.3 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 2.1% | — |
| CVE-2017-0043 | MED 5.3 | microsoft windows_10 Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Microsoft Active | 2.1% | — |
| CVE-2019-0838 | HIGH 7.8 | microsoft windows_10 An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839. | 2.1% | — |