Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

1,542

Total CVEs

1,542

CISA KEV

35

Known Exploits

9.3

Avg CVSS Score

Severity Distribution

HIGH 1542

Showing 20 of 418 CVEs matching "Microsoft"

CVE-2022-3723KEV
High

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 0.5%
CVE-2022-41033KEV
High

Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 1.2%
CVE-2022-41082KEV
High

Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.

MicrosoftEPSS 91.7%
CVE-2022-41040KEV
High

Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.

MicrosoftEPSS 94.2%
CVE-2010-2568KEV
High

Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user.

MicrosoftEPSS 92.1%
CVE-2022-37969KEV
High

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

MicrosoftEPSS 12.1%
CVE-2022-3075KEV
High

Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 2.1%
CVE-2022-21971KEV
High

Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.

MicrosoftEPSS 87.1%
CVE-2022-26923KEV
High

An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.

MicrosoftEPSS 91.4%
CVE-2022-2856KEV
High

Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 5.1%
CVE-2022-34713KEV
High

A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.

MicrosoftEPSS 4.5%
CVE-2022-22047KEV
High

Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges.

MicrosoftEPSS 1.3%
CVE-2022-26925KEV
High

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.

MicrosoftEPSS 37.4%
CVE-2021-30533KEV
High

Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 10.5%
CVE-2022-30190KEV
High

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.

MicrosoftEPSS 93.5%
CVE-2010-2572KEV
High

Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.

MicrosoftEPSS 74.7%
CVE-2019-5825KEV
High

Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 73.7%
CVE-2012-0151KEV
High

The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.

MicrosoftEPSS 89.0%
CVE-2016-1646KEV
High

Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly have another unspecified impact via crafted JavaScript code. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleEPSS 66.5%
CVE-2012-1889KEV
High

Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.

MicrosoftEPSS 92.9%