IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1258 HIGH 8.8 microsoft active_directory_authentication_library An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in the way the library caches tokens. This vulnerability allows an authenticated attacker to perform actions in context of another user. The auth 3.8%
CVE-2016-0171 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application 3.8%
CVE-2021-42291 HIGH 7.5 microsoft windows_server Active Directory Domain Services Elevation of Privilege Vulnerability 3.8%
CVE-2021-42282 HIGH 7.5 microsoft windows_server Active Directory Domain Services Elevation of Privilege Vulnerability 3.8%
CVE-2011-0045 HIGH 7.2 microsoft windows_xp The Trace Events functionality in the kernel in Microsoft Windows XP SP3 does not properly perform type conversion, which causes integer truncation and insufficient memory allocation and triggers a buffer overflow, which allows local users to gain privileges v 3.8%
CVE-2007-1213 HIGH 7.2 microsoft windows_2000 The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer. 3.8%
CVE-2015-2512 HIGH 7.2 microsoft windows_10 The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a craft 3.8%
CVE-2021-43907 CRIT 9.8 microsoft windows_subsystem_for_linux Visual Studio Code WSL Extension Remote Code Execution Vulnerability 3.8%
CVE-2000-0129 LOW 2.1 microsoft windows_95 Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file. 3.8%
CVE-1999-1097 MED 6.4 microsoft netmeeting Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty. 3.8%
CVE-2002-1150 MED 4.6 microsoft netmeeting The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL) and 3.8%
CVE-2020-1136 HIGH 7.8 microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri 3.8%
CVE-2020-1028 HIGH 7.8 microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri 3.8%
CVE-2017-11829 MED 5.5 microsoft windows_10 Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions. 3.8%
CVE-2017-8735 MED 4.3 microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user by redirecting the user to a specially crafted website, due to the way that Microsoft Edge parses HTTP content, aka "Microsoft Edge Spoofi 3.8%
CVE-2016-7214 LOW 3.3 microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to bypass the AS 3.8%
CVE-2019-0732 HIGH 7.8 microsoft windows_10 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'. 3.8%
CVE-2025-30388 HIGH 7.8 microsoft 365_copilot Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. 3.8%
CVE-2020-1315 MED 5.3 microsoft internet_explorer An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'. 3.8%
CVE-2020-1242 MED 5.3 microsoft edge An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'. 3.8%
CVE-2021-1691 HIGH 7.7 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 3.8%
CVE-2019-1188 HIGH 7.5 microsoft windows_10 A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accou 3.8%
CVE-2017-8714 HIGH 7.8 microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2,, Windows 10 1607, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from an authenticated user on a guest opera 3.8%
CVE-2010-3944 HIGH 7.2 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability." 3.8%
CVE-2020-1046 HIGH 7.8 microsoft .net_framework A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. To exploit the vulnerability, an attacker would need to be able to u 3.8%