56.571 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21269 | MED 4.3 | microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability | 4.6% | — |
| CVE-2026-20840 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 4.6% | — |
| CVE-2020-1097 | MED 6.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.</p> <p>Th | 4.6% | — |
| CVE-2018-0599 | HIGH 7.8 | microsoft windows Untrusted search path vulnerability in the installer of Visual C++ Redistributable allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 4.6% | — |
| CVE-2020-1449 | HIGH 7.8 | microsoft 365_apps A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, aka 'Microsoft Project Remote Code Execution Vulnerability'. | 4.6% | — |
| CVE-2020-17023 | HIGH 7.8 | microsoft visual_studio_code <p>A remote code execution vulnerability exists in Visual Studio Code when a user is tricked into opening a malicious 'package.json' file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If | 4.6% | — |
| CVE-2002-1981 | MED 5.0 | microsoft sql_server Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert setting | 4.6% | — |
| CVE-2021-31966 | HIGH 7.2 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 4.6% | — |
| CVE-2018-8370 | LOW 3.1 | microsoft edge A information disclosure vulnerability exists when WebAudio Library improperly handles audio requests, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. | 4.6% | — |
| CVE-2003-0496 | HIGH 7.2 | microsoft windows_2000 Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file. | 4.6% | — |
| CVE-2021-31950 | HIGH 7.6 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 4.6% | — |
| CVE-2020-0885 | MED 4.3 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows Graphics Component Information Disclosure Vulnerability'. | 4.6% | — |
| CVE-2019-0908 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 4.6% | — |
| CVE-2020-0706 | MED 4.3 | microsoft edge An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests, aka 'Microsoft Browser Information Disclosure Vulnerability'. | 4.6% | — |
| CVE-2017-0186 | MED 5.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a gu | 4.6% | — |
| CVE-2020-1503 | MED 5.5 | microsoft 365_apps An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, a | 4.6% | — |
| CVE-2020-0612 | HIGH 7.5 | microsoft windows_server_2016 A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerabil | 4.6% | — |
| CVE-2017-11877 | MED 5.5 | microsoft excel Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Compatibility Pack Service Pack 3, Microsoft Excel Viewer 2007 Service | 4.5% | — |
| CVE-2017-0109 | HIGH 7.6 | microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to execute arbitrary code on the host OS via a c | 4.5% | — |
| CVE-2015-0003 | MED 6.9 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain pr | 4.5% | — |
| CVE-2022-30147 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 4.5% | — |
| CVE-2005-0738 | MED 5.0 | microsoft exchange_server Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang a | 4.5% | — |
| CVE-2020-1267 | MED 4.9 | microsoft windows_10 This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request, aka 'Local Security Authority Subsystem Service Denial of Servic | 4.5% | — |
| CVE-2020-0922 | HIGH 8.8 | microsoft windows_10 <p>A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.</p> <p>To exploit the vulnerability, | 4.5% | — |
| CVE-2024-30032 | HIGH 7.8 | microsoft windows_10_1507 Windows DWM Core Library Elevation of Privilege Vulnerability | 4.5% | — |