IT
58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.469 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2012-1854 HIGH 7.8 microsoft office Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges v 21.0%
CVE-2023-36563 MED 6.5 microsoft windows_10_1507 Microsoft WordPad Information Disclosure Vulnerability 20.7%
CVE-2016-3309 HIGH 7.8 ransomware microsoft windows_10_1507 The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl 20.5%
CVE-2023-36761 MED 6.5 microsoft 365_apps Microsoft Word Information Disclosure Vulnerability 19.6%
CVE-2021-41379 MED 5.5 ransomware microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability 19.5%
CVE-2019-1215 HIGH 7.8 ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303. 19.3%
CVE-2019-1322 HIGH 7.8 ransomware microsoft windows_10_1803 An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340. 19.2%
CVE-2022-22047 HIGH 7.8 microsoft windows_10_1507 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability 18.8%
CVE-2024-7965 HIGH 8.8 google chrome Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 18.5%
CVE-2022-22718 HIGH 7.8 microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability 18.5%
CVE-2018-8440 HIGH 7.8 ransomware microsoft windows_10_1607 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve 18.4%
CVE-2017-0022 MED 6.5 microsoft windows_8.1 Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in me 18.1%
CVE-2026-55040 CRIT 9.1 microsoft sharepoint_server Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. 17.5%
CVE-2022-26904 HIGH 7.0 microsoft windows_10_1507 Windows User Profile Service Elevation of Privilege Vulnerability 16.9%
CVE-2023-36036 HIGH 7.8 microsoft windows_10_1507 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 16.7%
CVE-2023-6345 CRIT 9.6 debian debian_linux Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) 16.5%
CVE-2020-0986 HIGH 7.8 microsoft windows_10_1507 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, 16.3%
CVE-2026-58644 CRIT 9.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. 15.9%
CVE-2026-21513 HIGH 8.8 microsoft windows_10_1607 Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. 15.6%
CVE-2023-35311 HIGH 8.8 microsoft 365_apps Microsoft Outlook Security Feature Bypass Vulnerability 15.5%
CVE-2022-38028 HIGH 7.8 microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability 14.9%
CVE-2015-2360 HIGH 8.8 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users 14.8%
CVE-2024-49039 HIGH 8.8 ransomware microsoft windows_10_1507 Windows Task Scheduler Elevation of Privilege Vulnerability 14.2%
CVE-2023-38180 HIGH 7.5 fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability 14.0%
CVE-2025-29824 HIGH 7.8 ransomware microsoft windows_10_1507 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 13.9%