Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Office HIGH 7.8
CVE-2017-0030EPSS 26%

Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Office Web Apps Server 2010 SP2, Word 2007 SP3, Word 2010 SP2, and Word Automation Services…

Patch available
Fix from $1,950 2017-03-17
Office HIGH 7.8
CVE-2017-0031EPSS 26%

Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, and Word 2010 SP2 allow remote attackers to execute arbitrary code or cause …

Patch available
Fix from $1,950 2017-03-17
Edge HIGH 7.5
CVE-2017-0010EPSS 27%

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft brow…

Patch available
Fix from $1,950 2017-03-17
Office HIGH 7.5
CVE-2017-0014EPSS 18%

The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;…

Patch available
Fix from $1,950 2017-03-17
Edge HIGH 7.5
CVE-2017-0015EPSS 26%

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft brow…

Patch available
Fix from $1,950 2017-03-17
Edge HIGH 7.5
CVE-2017-0023EPSS 34%

The PDF library in Microsoft Edge; Windows 8.1; Windows Server 2012 and R2; Windows RT 8.1; and Windows 10, 1511, and 1607 allows remote attackers to…

Patch available
Fix from $1,950 2017-03-17
Edge HIGH 7.5
CVE-2017-0032EPSS 15%

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft brow…

Patch available
Fix from $1,950 2017-03-17
Xml Core Services MEDIUM 6.5
CVE-2017-0022 KEVEPSS 18%

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP…

Patch available
Fix from $1,600 2017-03-17
Edge MEDIUM 6.1
CVE-2017-0017EPSS 42%

The RegEx class in the XSS filter in Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive inform…

Patch available
Fix from $1,600 2017-03-17
Windows 10 MEDIUM 5.9
CVE-2017-0016EPSS 26%

Microsoft Windows 10 Gold, 1511, and 1607; Windows 8.1; Windows RT 8.1; Windows Server 2012 R2, and Windows Server 2016 do not properly handle certai…

Patch available
Fix from $1,600 2017-03-17
Windows 10 MEDIUM 5.5
CVE-2017-0007EPSS 11%

Device Guard in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to modify PowerShell script without invalidati…

Patch available
Fix from $1,600 2017-03-17
Office MEDIUM 5.5
CVE-2017-0029EPSS 16%

Microsoft Office 2010 SP2, Word 2010 SP2, Word 2013 RT SP1, and Word 2016 allow remote attackers to cause a denial of service (application hang) via …

Patch available
Fix from $1,600 2017-03-17
Edge HIGH 8.1
CVE-2017-0037 KEVEPSS 80%

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnS…

Patch available
Fix from $1,950 2017-02-26
Windows 10 MEDIUM 5.5
CVE-2017-0038EPSS 82%

gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows …

Patch available
Fix from $1,600 2017-02-20
Skype HIGH 7.8
CVE-2016-5720

Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduct DLL hijacking attacks via a…

Mitigation only
Fix from $1,950 2017-01-23
Edge HIGH 8.8
CVE-2017-0002EPSS 15%

Microsoft Edge allows remote attackers to bypass the Same Origin Policy via vectors involving the about:blank URL and data: URLs, aka "Microsoft Edge…

Mitigation only
Fix from $1,950 2017-01-10
Sharepoint Enterprise Server HIGH 7.8
CVE-2017-0003EPSS 25%

Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Off…

Mitigation only
Fix from $1,950 2017-01-10
Publisher HIGH 7.8
CVE-2016-7289EPSS 25%

Microsoft Publisher 2010 SP2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted documen…

Mitigation only
Fix from $1,950 2016-12-20
Windows 10 HIGH 7.8
CVE-2016-7292

The Installer in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window…

Mitigation only
Fix from $1,950 2016-12-20
Office HIGH 7.8
CVE-2016-7298EPSS 23%

Microsoft Office 2007 SP3, Office 2010 SP2, Word Viewer, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2016-12-20
Auto Updater For Mac HIGH 7.8
CVE-2016-7300

Untrusted search path vulnerability in Microsoft Auto Updater for Mac allows local users to gain privileges via a Trojan horse executable file, aka "…

Mitigation only
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7286EPSS 69%

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

No fix yet
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7287EPSS 69%

The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of serv…

No fix yet
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7288EPSS 70%

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

No fix yet
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7296EPSS 17%

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

Mitigation only
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7297EPSS 27%

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

Mitigation only
Fix from $1,950 2016-12-20
Office HIGH 7.1
CVE-2016-7290EPSS 23%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Ser…

Mitigation only
Fix from $1,950 2016-12-20
Office HIGH 7.1
CVE-2016-7291EPSS 23%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Ser…

Mitigation only
Fix from $1,950 2016-12-20
Edge MEDIUM 6.1
CVE-2016-7280EPSS 9%

Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, ak…

Mitigation only
Fix from $1,600 2016-12-20
Edge MEDIUM 6.1
CVE-2016-7282EPSS 10%

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to inject arbitrary w…

Mitigation only
Fix from $1,600 2016-12-20