IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2017-0159 LOW 3.7 microsoft windows_10 A security feature bypass vulnerability exists in Windows 10 1607, Windows Server 2012 R2, and Windows 2016 when ADFS incorrectly treats requests coming from Extranet clients as Intranet requests, aka "ADFS Security Feature Bypass Vulnerability." 3.6%
CVE-2005-3981 MED 4.9 microsoft windows_2000 NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess fun 3.6%
CVE-2026-23668 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 3.6%
CVE-2015-2507 HIGH 7.2 microsoft windows_10 The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a craft 3.6%
CVE-2026-21511 HIGH 7.5 microsoft 365_apps Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. 3.6%
CVE-2020-1594 HIGH 7.8 microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If t 3.6%
CVE-2020-1338 HIGH 7.8 microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security contex 3.6%
CVE-2020-1335 HIGH 7.8 microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If t 3.6%
CVE-2020-1332 HIGH 7.8 microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If t 3.6%
CVE-2020-1218 HIGH 7.8 microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security contex 3.6%
CVE-2020-1193 HIGH 7.8 microsoft 365_apps <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If t 3.6%
CVE-2019-0764 MED 6.5 microsoft edge A tampering vulnerability exists when Microsoft browsers do not properly validate input under specific conditions, aka 'Microsoft Browsers Tampering Vulnerability'. 3.6%
CVE-2020-17085 MED 6.2 microsoft exchange_server Microsoft Exchange Server Denial of Service Vulnerability 3.6%
CVE-2021-1665 HIGH 7.8 microsoft windows_10 GDI+ Remote Code Execution Vulnerability 3.6%
CVE-2022-21917 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 3.6%
CVE-2018-0799 MED 6.1 microsoft sharepoint_enterprise_server Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka "Microsoft Access Tampering Vulnerability". 3.6%
CVE-2026-45586 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally. 3.6%
CVE-2024-43630 HIGH 7.8 microsoft windows_10_21h2 Windows Kernel Elevation of Privilege Vulnerability 3.6%
CVE-2021-1668 HIGH 7.8 microsoft windows_10 Microsoft DTV-DVD Video Decoder Remote Code Execution Vulnerability 3.6%
CVE-2025-21420 HIGH 7.8 microsoft windows_10_1507 Windows Disk Cleanup Tool Elevation of Privilege Vulnerability 3.6%
CVE-2020-0604 HIGH 7.8 microsoft visual_studio_code A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the curre 3.6%
CVE-1999-1128 MED 5.1 microsoft internet_explorer Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user. 3.6%
CVE-2017-8613 HIGH 8.1 microsoft azure_active_directory_connect Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege Vulnerability." 3.6%
CVE-2018-0968 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." T 3.6%
CVE-2018-8388 MED 4.3 microsoft edge A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8383. 3.6%