IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-1667 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 3.6%
CVE-2024-21312 HIGH 7.5 microsoft .net_framework .NET Framework Denial of Service Vulnerability 3.6%
CVE-2023-24912 HIGH 7.8 microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability 3.6%
CVE-2021-26415 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 3.6%
CVE-2021-1734 HIGH 7.5 microsoft windows_10 Windows Remote Procedure Call Information Disclosure Vulnerability 3.6%
CVE-2020-1487 HIGH 7.8 microsoft windows_10 An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability 3.6%
CVE-2023-21812 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 3.6%
CVE-2019-1338 MED 5.9 microsoft windows_7 A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLMv2 protection if a client is also sending LMv2 responses, aka 'Windows NTLM Security Feature Bypass Vulnerability'. 3.6%
CVE-2015-2554 HIGH 7.2 microsoft windows_10 The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Object Reference Elevation of Privilege Vulnerability." 3.6%
CVE-2020-17148 HIGH 7.8 microsoft visual_studio_code Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability 3.6%
CVE-2022-24464 HIGH 7.5 fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability 3.6%
CVE-2020-1467 CRIT 10.0 microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would 3.5%
CVE-2023-35380 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 3.5%
CVE-2020-17019 HIGH 7.8 microsoft office Microsoft Excel Remote Code Execution Vulnerability 3.5%
CVE-2015-0004 HIGH 7.2 microsoft windows_7 The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain p 3.5%
CVE-2024-30035 HIGH 7.8 microsoft windows_10_1809 Windows DWM Core Library Elevation of Privilege Vulnerability 3.5%
CVE-2017-0256 MED 5.3 microsoft asp.net_model_view_controller A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. 3.5%
CVE-2021-26433 HIGH 7.5 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability 3.5%
CVE-2021-27058 HIGH 7.8 microsoft 365_apps Microsoft Office ClickToRun Remote Code Execution Vulnerability 3.5%
CVE-2023-21552 HIGH 7.8 microsoft windows_10_1607 Windows GDI Elevation of Privilege Vulnerability 3.5%
CVE-2020-24588 LOW 3.5 arista c-100_firmware The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU fr 3.5%
CVE-2019-0813 CRIT 9.8 microsoft windows_admin_center An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'Windows Admin Center Elevation of Privilege Vulnerability'. 3.5%
CVE-2021-42284 MED 6.8 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 3.5%
CVE-2023-24892 HIGH 8.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability 3.5%
CVE-2019-1318 MED 5.9 microsoft windows_10 A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'. 3.5%