Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

1,542

Total CVEs

1,542

CISA KEV

35

Known Exploits

9.3

Avg CVSS Score

Severity Distribution

HIGH 1542

Showing 20 of 418 CVEs matching "Microsoft"

CVE-2024-49039KEV
High

Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.

MicrosoftEPSS 65.9%
CVE-2024-43451KEV
High

Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.

MicrosoftEPSS 90.3%
CVE-2024-38094KEV
High

Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.

MicrosoftEPSS 64.3%
CVE-2024-30088KEV
High

Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.

MicrosoftEPSS 85.2%
CVE-2024-43573KEV
High

Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality.

MicrosoftEPSS 18.6%
CVE-2024-43572KEV
High

Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution.

MicrosoftEPSS 44.6%
CVE-2020-0618KEV
High

Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.

MicrosoftEPSS 94.3%
CVE-2024-43461KEV
High

Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112.

MicrosoftEPSS 9.8%
CVE-2024-38217KEV
High

Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.

MicrosoftEPSS 13.2%
CVE-2024-38226KEV
High

Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files.

MicrosoftEPSS 1.4%
CVE-2024-38014KEV
High

Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges.

MicrosoftEPSS 12.8%
CVE-2024-7965KEV
High

Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 27.1%
CVE-2024-7971KEV
High

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 1.0%
CVE-2021-31196KEV
High

Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.

MicrosoftEPSS 3.3%
CVE-2024-38193KEV
High

Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.

MicrosoftEPSS 74.8%
CVE-2024-38107KEV
High

Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges.

MicrosoftEPSS 3.4%
CVE-2024-38106KEV
High

Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an attacker to win a race condition.

MicrosoftEPSS 0.8%
CVE-2024-38213KEV
High

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file.

MicrosoftEPSS 59.3%
CVE-2024-38178KEV
High

Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL.

MicrosoftEPSS 26.3%
CVE-2024-38189KEV
High

Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file.

MicrosoftEPSS 43.7%