← Back

Microsoft

microsoft

15,064 CVEs • 1,059 products

Products (1,059)

Click to collapse
Toggle
Windows 10
windows_10
Windows 7
windows_7
Windows 8.1
windows_8.1
Office
office
Edge
edge
Windows Xp
windows_xp
365 Apps
365_apps
Windows 11
windows_11
Windows 2000
windows_2000
Excel
excel
Word
word
Windows Nt
windows_nt
Chakracore
chakracore
Windows 8
windows_8
Windows Rt
windows_rt
Ie
ie
Office 2024
office_2024
Office 2021
office_2021
Office 2019
office_2019
Excel Viewer
excel_viewer
Outlook
outlook
Sql Server
sql_server
Dynamics 365
dynamics_365
.net
Windows 98
windows_98
Word Viewer
word_viewer
Powerpoint
powerpoint
Windows
windows
Windows 98se
windows_98se
Works
works
Windows Me
windows_me
Visual Studio
visual_studio
Visio
visio
365 Copilot
365_copilot
Windows 95
windows_95
Publisher
publisher
Lync
lync
Office 2016
office_2016
Asp.net Core
asp.net_core

CVEs (15,064)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Internet Explorer
Apr 16, 2026
Apr 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
Remote command execution in Microsoft Internet Explorer using .lnk and .url files.
1Microsoft
1Internet Explorer
Apr 16, 2026
Mar 1, 1997
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.
2Gnu
Microsoft
4Finger Service
FingerdWindows 2000+1 more
Apr 16, 2026
Mar 1, 1997
N/A· v4
N/A· v3
0.0 LOW· v2
A version of finger is running that exposes valid user information to any entity on the network.
1Microsoft
1Windows Nt
Apr 16, 2026
Feb 7, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.
1Microsoft
1Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.
1Microsoft
1Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdo...Show more
A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking.Show less
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
9.3 HIGH· v2
.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
The registry in Windows NT can be accessed remotely by users who are not administrators.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
10.0 HIGH· v2
A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
4.6 MEDIUM· v2
A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Incr...Show more
A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input.Show less
1Microsoft
4Outlook
Windows 2000Windows 95+1 more
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
A NETBIOS/SMB share password is the default, null, or missing.
1Microsoft
1Windows 95
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
A NETBIOS/SMB share password is guessable.
1Microsoft
2Windows 2000
Windows Nt
May 28, 2026
Jan 1, 1997
N/A· v4
9.1 CRITICAL· v3
7.5 HIGH· v2
IP forwarding is enabled on a machine which is not a router or firewall.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
A Windows NT local user or administrator account has a default, null, blank, or missing password.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.2 HIGH· v2
A Windows NT local user or administrator account has a guessable password.
1Microsoft
2Windows 2000
Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
NETBIOS share information may be published through SNMP registry keys in NT.
1Microsoft
1Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.2 HIGH· v2
A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.
1Microsoft
1Windows Nt
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.
1Microsoft
2Internet Information Server
Internet Information Services
Apr 16, 2026
Jan 1, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.