Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,234

Total CVEs

1,589

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1599
MEDIUM 7
INFO 620

Showing 20 of 428 CVEs matching "Microsoft" · CISA KEV

CVE-2016-0162KEV
High

An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer.

MicrosoftEPSS 38.0%
CVE-2017-0147KEV
High

The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.

MicrosoftEPSS 92.4%
CVE-2017-0149KEV
High

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website.

MicrosoftEPSS 41.5%
CVE-2018-8611KEV
High

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.

MicrosoftEPSS 16.4%
CVE-2017-0005KEV
High

The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.

MicrosoftEPSS 8.0%
CVE-2017-0210KEV
High

A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.

MicrosoftEPSS 38.0%
CVE-2017-0022KEV
High

Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.

MicrosoftEPSS 44.1%
CVE-2017-8543KEV
High

Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.

MicrosoftEPSS 83.8%
CVE-2020-0638KEV
High

Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 1.7%
CVE-2020-1027KEV
High

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.

MicrosoftEPSS 11.9%
CVE-2019-1130KEV
High

A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.

MicrosoftEPSS 1.9%
CVE-2019-1385KEV
High

A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.

MicrosoftEPSS 0.4%
CVE-2019-0880KEV
High

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.

MicrosoftEPSS 4.1%
CVE-2019-0703KEV
High

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server.

MicrosoftEPSS 23.2%
CVE-2019-0676KEV
High

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of files on disk.

MicrosoftEPSS 23.8%
CVE-2018-8589KEV
High

A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.

MicrosoftEPSS 46.3%
CVE-2014-4113KEV
High

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 82.4%
CVE-2014-0322KEV
High

Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.

MicrosoftEPSS 93.2%
CVE-2022-21919KEV
High

Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 0.3%
CVE-2021-41357KEV
High

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 7.4%