Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,234

Total CVEs

1,589

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1599
MEDIUM 7
INFO 620

Showing 20 of 428 CVEs matching "Microsoft" · HIGH

CVE-2018-8453KEV
High

Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.

MicrosoftEPSS 78.2%
CVE-2021-33766KEV
High

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.

MicrosoftEPSS 93.7%
CVE-2019-1458KEV
High

A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.

MicrosoftEPSS 91.9%
CVE-2013-3900KEV
High

A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.

MicrosoftEPSS 80.2%
CVE-2021-4102KEV
High

Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 4.4%
CVE-2021-43890KEV
High

Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.

MicrosoftEPSS 16.4%
CVE-2021-42292KEV
High

A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.

MicrosoftEPSS 19.1%
CVE-2021-42321KEV
High

An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.

MicrosoftEPSS 93.4%
CVE-2021-40449KEV
High

Unspecified vulnerability allows for an authenticated user to escalate privileges.

MicrosoftEPSS 91.1%
CVE-2017-11774KEV
High

Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.

MicrosoftEPSS 82.9%
CVE-2019-1367KEV
High

Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.

MicrosoftEPSS 89.7%
CVE-2021-1732KEV
High

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 90.4%
CVE-2021-31207KEV
High

Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.

MicrosoftEPSS 93.8%
CVE-2020-0968KEV
High

Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

MicrosoftEPSS 33.4%
CVE-2019-1429KEV
High

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

MicrosoftEPSS 83.0%
CVE-2021-28310KEV
High

Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 27.8%
CVE-2019-0797KEV
High

Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

MicrosoftEPSS 6.1%
CVE-2017-0199KEV
High

Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.

MicrosoftEPSS 94.3%
CVE-2021-26411KEV
High

Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.

MicrosoftEPSS 92.5%
CVE-2020-1380KEV
High

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

MicrosoftEPSS 91.7%