56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1258 | HIGH 8.8 | microsoft active_directory_authentication_library An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in the way the library caches tokens. This vulnerability allows an authenticated attacker to perform actions in context of another user. The auth | 3.8% | — |
| CVE-2016-0171 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application | 3.8% | — |
| CVE-2021-42291 | HIGH 7.5 | microsoft windows_server Active Directory Domain Services Elevation of Privilege Vulnerability | 3.8% | — |
| CVE-2021-42282 | HIGH 7.5 | microsoft windows_server Active Directory Domain Services Elevation of Privilege Vulnerability | 3.8% | — |
| CVE-2011-0045 | HIGH 7.2 | microsoft windows_xp The Trace Events functionality in the kernel in Microsoft Windows XP SP3 does not properly perform type conversion, which causes integer truncation and insufficient memory allocation and triggers a buffer overflow, which allows local users to gain privileges v | 3.8% | — |
| CVE-2007-1213 | HIGH 7.2 | microsoft windows_2000 The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer. | 3.8% | — |
| CVE-2015-2512 | HIGH 7.2 | microsoft windows_10 The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a craft | 3.8% | — |
| CVE-2021-43907 | CRIT 9.8 | microsoft windows_subsystem_for_linux Visual Studio Code WSL Extension Remote Code Execution Vulnerability | 3.8% | — |
| CVE-2000-0129 | LOW 2.1 | microsoft windows_95 Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file. | 3.8% | — |
| CVE-1999-1097 | MED 6.4 | microsoft netmeeting Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty. | 3.8% | — |
| CVE-2002-1150 | MED 4.6 | microsoft netmeeting The Remote Desktop Sharing (RDS) Screen Saver Protection capability for Microsoft NetMeeting 3.01 through SP2 (4.4.3396) allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences (such as CTRL-ALT-DEL) and | 3.8% | — |
| CVE-2020-1136 | HIGH 7.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 3.8% | — |
| CVE-2020-1028 | HIGH 7.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 3.8% | — |
| CVE-2017-11829 | MED 5.5 | microsoft windows_10 Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions. | 3.8% | — |
| CVE-2017-8735 | MED 4.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user by redirecting the user to a specially crafted website, due to the way that Microsoft Edge parses HTTP content, aka "Microsoft Edge Spoofi | 3.8% | — |
| CVE-2016-7214 | LOW 3.3 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to bypass the AS | 3.8% | — |
| CVE-2019-0732 | HIGH 7.8 | microsoft windows_10 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'. | 3.8% | — |
| CVE-2025-30388 | HIGH 7.8 | microsoft 365_copilot Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | 3.8% | — |
| CVE-2020-1315 | MED 5.3 | microsoft internet_explorer An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'. | 3.8% | — |
| CVE-2020-1242 | MED 5.3 | microsoft edge An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'. | 3.8% | — |
| CVE-2021-1691 | HIGH 7.7 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 3.8% | — |
| CVE-2019-1188 | HIGH 7.5 | microsoft windows_10 A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accou | 3.8% | — |
| CVE-2017-8714 | HIGH 7.8 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2,, Windows 10 1607, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from an authenticated user on a guest opera | 3.8% | — |
| CVE-2010-3944 | HIGH 7.2 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability." | 3.8% | — |
| CVE-2020-1046 | HIGH 7.8 | microsoft .net_framework A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. To exploit the vulnerability, an attacker would need to be able to u | 3.8% | — |