Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,234

Total CVEs

1,589

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1599
MEDIUM 7
INFO 620

Showing 20 of 428 CVEs matching "Microsoft" · HIGH

CVE-2023-38180KEV
High

Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS).

MicrosoftEPSS 0.9%
CVE-2023-36884KEV
High

Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.

MicrosoftEPSS 93.2%
CVE-2023-32046KEV
High

Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 42.7%
CVE-2023-36874KEV
High

Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 71.2%
CVE-2023-35311KEV
High

Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.

MicrosoftEPSS 0.5%
CVE-2023-32049KEV
High

Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt.

MicrosoftEPSS 9.1%
CVE-2016-0165KEV
High

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 9.0%
CVE-2023-3079KEV
High

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 1.5%
CVE-2023-34362KEV
High

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

ProgressEPSS 94.3%
CVE-2023-29336KEV
High

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges.

MicrosoftEPSS 79.5%
CVE-2023-2033KEV
High

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 24.3%
CVE-2023-28252KEV
High

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 56.5%
CVE-2019-1388KEV
High

Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.

MicrosoftEPSS 7.3%
CVE-2013-3163KEV
High

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website.

MicrosoftEPSS 82.9%
CVE-2022-3038KEV
High

Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 36.0%
CVE-2023-23397KEV
High

Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.

MicrosoftEPSS 93.6%
CVE-2023-24880KEV
High

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

MicrosoftEPSS 77.3%
CVE-2023-23376KEV
High

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 21.1%
CVE-2023-21823KEV
High

Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 5.2%
CVE-2023-21715KEV
High

Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.

MicrosoftEPSS 0.7%