Analyst command view

MSRC Driver CVE Board

Latest-state board for filtered MSRC CVEs from 2020-01-01 to today, tuned for fast triage across module, CWE, release window, exploitation signal, and acknowledgement context.

Live snapshot
Last Sync
2026-05-20T07:39:30Z
Freshness
1 day(s) ago
Refresh Policy
24h baseline + release watch
Storage
Latest snapshot only
Rows In View
108
Current result set after filter and search.
Exploited Flagged
66
Rows with a non-empty exploitation signal.
Distinct CWE
2
Unique weakness classes in this view.
Modules
72
Unique inferred driver or component labels.
Reset
Active filters CWE CWE-400: Uncontrolled Resource Consumption Clear filters
Release Month
October 2024
5 CVE | last update 1 day(s) ago
Release 2024-10-08 Patch Tuesday Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-43545
Windows Online Certificate Status Protocol (OCSP) Server
Exploitation Less Likely
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-10-08 No
Reported By
CVE-2024-43575
Windows Hyper-V
Exploitation Less Likely
Windows Hyper-V Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-10-08 No
Reported By
CVE-2024-43544
Microsoft Simple Certificate Enrollment Protocol
Exploitation Less Likely
Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-10-08 No
Reported By
CVE-2024-43541
Microsoft Simple Certificate Enrollment Protocol
Exploitation Less Likely
Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-10-08 No
Reported By
CVE-2024-43515
Internet Small Computer Systems Interface (iSCSI)
Exploitation Less Likely
Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-10-08 No
Reported By
Release Month
September 2024
2 CVE | last update 1 day(s) ago
Release 2024-09-11 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-42836
GJSON before 1.9.3 allows a ReDoS (regular expression
No latest release note
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2024-09-11 - -
Release 2024-09-10 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-38236
DHCP Server Service
Exploitation Less Likely
DHCP Server Service Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-09-10 No
Reported By
Anonymous
Release Month
July 2024
7 CVE | last update 1 day(s) ago
Release 2024-07-13 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2017-18214
The moment module before 2.19.3 for Node.js is prone to a regular expression
No latest release note
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string a different vulnerability than CVE-2016-4055.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2024-07-13 - -
Release 2024-07-09 Patch Tuesday Count 6
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-35270
Windows iSCSI Service
Exploitation Less Likely
Windows iSCSI Service Denial of Service Vulnerability
CVSS vector: AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-07-09 No
Reported By
CVE-2024-38015
Windows Remote Desktop Gateway (RD Gateway)
Exploitation Less Likely
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-07-09 No
CVE-2024-38068
Windows Online Certificate Status Protocol (OCSP) Server
Exploitation Less Likely
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-07-09 No
Reported By
CVE-2024-38067
Windows Online Certificate Status Protocol (OCSP) Server
Exploitation Less Likely
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-07-09 No
Reported By
CVE-2024-38031
Windows Online Certificate Status Protocol (OCSP) Server
Exploitation Less Likely
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-07-09 No
Reported By
CVE-2024-38027
Windows Line Printer Daemon Service
Exploitation Less Likely
Windows Line Printer Daemon Service Denial of Service Vulnerability
CVSS vector: AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-07-09 No
Reported By
Anonymous
bobo and bee13oy with Cyber Kunlun Lab
Release Month
June 2024
3 CVE | last update 1 day(s) ago
Release 2024-06-30 Other / OOB Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-28863
node-tar vulnerable to
No latest release note
node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2024-06-30 - -
CVE-2024-37535
GNOME VTE before 0.76.3 allows an attacker to cause a
No latest release note
GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence a related issue to CVE-2000-0476.
CVSS vector: AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
2024-06-30 - -
CVE-2023-46118
Denial of Service by publishing large messages over the HTTP API
No latest release note
Denial of Service by publishing large messages over the HTTP API
CVSS vector: AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
2024-06-30 - -
Release Month
May 2024
2 CVE | last update 1 day(s) ago
Release 2024-05-19 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-35176
REXML contains a
No latest release note
REXML contains a denial of service vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
2024-05-19 - -
Release 2024-05-14 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-30019
DHCP Server Service
Exploitation Less Likely
DHCP Server Service Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-05-14 No
Reported By
Anonymous
Release Month
April 2024
2 CVE | last update 1 day(s) ago
Release 2024-04-09 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-26215
DHCP Server Service
Exploitation Less Likely
DHCP Server Service Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:H/RL:O/RC:C
2024-04-09 No
Reported By
Anonymous
CVE-2024-26212
DHCP Server Service
Exploitation More Likely
DHCP Server Service Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-04-09 No
Reported By
Anonymous
Release Month
March 2024
1 CVE | last update 1 day(s) ago
Release 2024-03-12 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-26190
Microsoft QUIC
Exploitation Less Likely
Microsoft QUIC Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-03-12 No -
Release Month
February 2024
3 CVE | last update 1 day(s) ago
Release 2024-02-16 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-24575
libgit2 is vulnerable to a
No latest release note
libgit2 is vulnerable to a denial of service attack in `git_revparse_single`
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2024-02-16 - -
Release 2024-02-13 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2024-21342
Windows DNS Client
Exploitation Less Likely
Windows DNS Client Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2024-02-13 No
Reported By
Anonymous
Release 2024-02-09 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-52425
libexpat through 2.5.0 allows a
No latest release note
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2024-02-09 - -
Release Month
January 2024
1 CVE | last update 1 day(s) ago
Release 2024-01-16 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-49295
quic-go's path validation mechanism can cause
No latest release note
quic-go's path validation mechanism can cause denial of service
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2024-01-16 - -
Release Month
October 2023
5 CVE | last update 1 day(s) ago
Release 2023-10-10 Patch Tuesday Count 5
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-36435
Microsoft QUIC
Exploitation Less Likely
Microsoft QUIC Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-10-10 No
Reported By
ziming zhang with Ant Security Light-Year Lab
CVE-2023-36606
Microsoft Message Queuing (MSMQ)
Exploitation Less Likely
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-10-10 No
Reported By
CVE-2023-36579
Microsoft Message Queuing (MSMQ)
Exploitation Less Likely
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-10-10 No
Reported By
CVE-2023-36431
Microsoft Message Queuing (MSMQ)
Exploitation Less Likely
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-10-10 No
Reported By
CVE-2023-36703
DHCP Server Service
Exploitation Less Likely
DHCP Server Service Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-10-10 No
Release Month
September 2023
1 CVE | last update 1 day(s) ago
Release 2023-09-12 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-38149
Windows TCP/IP
Exploitation Less Likely
Windows TCP/IP Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-09-12 No
Reported By
Wei in Kunlun Lab with Cyber KunLun
Release Month
July 2023
3 CVE | last update 1 day(s) ago
Release 2023-07-11 Patch Tuesday Count 3
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-35339
Windows CryptoAPI
Exploitation Less Likely
Windows CryptoAPI Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-07-11 No
Reported By
CVE-2023-35329
Windows Authentication
Exploitation Less Likely
Windows Authentication Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-07-11 No
Reported By
Anonymous
CVE-2023-35298
HTTP.sys
Exploitation Less Likely
HTTP.sys Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-07-11 No
Reported By
Hong Hai with Alibaba Orion Security Lab
Release Month
June 2023
2 CVE | last update 1 day(s) ago
Release 2023-06-13 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-33141
Yet Another Reverse Proxy (YARP)
Exploitation Less Likely
Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
2023-06-13 No -
CVE-2023-32013
Windows Hyper-V
Exploitation Less Likely
Windows Hyper-V Denial of Service Vulnerability
CVSS vector: AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-06-13 No
Reported By
Maxime Villard, of M.O.R.S.E.
Release Month
May 2023
1 CVE | last update 1 day(s) ago
Release 2023-05-29 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-30570
pluto in Libreswan before 4.11 allows a
No latest release note
pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2023-05-29 - -
Release Month
April 2023
1 CVE | last update 1 day(s) ago
Release 2023-04-11 Patch Tuesday Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-28217
Windows Network Address Translation (NAT)
Exploitation Less Likely
Windows Network Address Translation (NAT) Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-04-11 No
Reported By
Microsoft WSD EPIN CoreNET
Release Month
January 2023
3 CVE | last update 1 day(s) ago
Release 2023-01-20 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2022-4344
Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows
No latest release note
Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file
CVSS vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
2023-01-20 - -
Release 2023-01-10 Patch Tuesday Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2023-21728
Windows Netlogon
Exploitation Less Likely
Windows Netlogon Denial of Service Vulnerability
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
2023-01-10 No
Reported By
bee13oy with Cyber Kunlun Lab
CVE-2023-21543
Windows Layer 2 Tunneling Protocol (L2TP)
Exploitation Less Likely
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
CVSS vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
2023-01-10 No
Reported By
Release Month
November 2022
1 CVE | last update 1 day(s) ago
Release 2022-11-09 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2022-40617
strongSwan before 5.9.8 allows remote attackers to cause a
No latest release note
strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing after the initial TCP handshake or sends an excessive amount of application data.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2022-11-09 - -
Release Month
June 2022
2 CVE | last update 1 day(s) ago
Release 2022-06-09 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2020-28493
Regular Expression
No latest release note
Regular Expression Denial of Service (ReDoS)
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
2022-06-09 - -
Release 2022-06-02 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-3733
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to could trigger a Regular Expression
No latest release note
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
CVSS vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2022-06-02 - -
Release Month
January 2022
1 CVE | last update 1 day(s) ago
Release 2022-01-19 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-32617
Exiv2
No latest release note
Denial of service in Exiv2
CVSS vector: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
2022-01-19 - -
Release Month
July 2021
2 CVE | last update 1 day(s) ago
Release 2021-07-30 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-32740
Regular Expression
No latest release note
Regular Expression Denial of Service in Addressable templates
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-07-30 - -
Release 2021-07-03 Other / OOB Count 1
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2021-33503
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a
No latest release note
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-07-03 - -
Release Month
June 2021
2 CVE | last update 1 day(s) ago
Release 2021-06-06 Other / OOB Count 2
CVE Module CWE Title Advisory text and compact technical context Release Exploited Acknowledgement
CVE-2018-12122
Node.js: All versions prior to Node.js 6.15.0 8.14.0 10.14.0 and 11.3.0: Slowloris HTTP
No latest release note
Node.js: All versions prior to Node.js 6.15.0 8.14.0 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-06-06 - -
CVE-2018-12121
Node.js: All versions prior to Node.js 6.15.0 8.14.0 10.14.0 and 11.3.0
No latest release note
Node.js: All versions prior to Node.js 6.15.0 8.14.0 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection) and carefully timed completion of the headers it is possible to cause the HTTP server to abort from heap allocation failure. Attack potential is mitigated by the use of a load balancer or other proxy layer.
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2021-06-06 - -
Prev Page 2 / 3 | rows 51-100 of 108 Next