56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1667 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 3.6% | — |
| CVE-2024-21312 | HIGH 7.5 | microsoft .net_framework .NET Framework Denial of Service Vulnerability | 3.6% | — |
| CVE-2023-24912 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 3.6% | — |
| CVE-2021-26415 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 3.6% | — |
| CVE-2021-1734 | HIGH 7.5 | microsoft windows_10 Windows Remote Procedure Call Information Disclosure Vulnerability | 3.6% | — |
| CVE-2020-1487 | HIGH 7.8 | microsoft windows_10 An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability | 3.6% | — |
| CVE-2023-21812 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 3.6% | — |
| CVE-2019-1338 | MED 5.9 | microsoft windows_7 A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLMv2 protection if a client is also sending LMv2 responses, aka 'Windows NTLM Security Feature Bypass Vulnerability'. | 3.6% | — |
| CVE-2015-2554 | HIGH 7.2 | microsoft windows_10 The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Object Reference Elevation of Privilege Vulnerability." | 3.6% | — |
| CVE-2020-17148 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability | 3.6% | — |
| CVE-2022-24464 | HIGH 7.5 | fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability | 3.6% | — |
| CVE-2020-1467 | CRIT 10.0 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would | 3.5% | — |
| CVE-2023-35380 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 3.5% | — |
| CVE-2020-17019 | HIGH 7.8 | microsoft office Microsoft Excel Remote Code Execution Vulnerability | 3.5% | — |
| CVE-2015-0004 | HIGH 7.2 | microsoft windows_7 The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain p | 3.5% | — |
| CVE-2024-30035 | HIGH 7.8 | microsoft windows_10_1809 Windows DWM Core Library Elevation of Privilege Vulnerability | 3.5% | — |
| CVE-2017-0256 | MED 5.3 | microsoft asp.net_model_view_controller A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | 3.5% | — |
| CVE-2021-26433 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 3.5% | — |
| CVE-2021-27058 | HIGH 7.8 | microsoft 365_apps Microsoft Office ClickToRun Remote Code Execution Vulnerability | 3.5% | — |
| CVE-2023-21552 | HIGH 7.8 | microsoft windows_10_1607 Windows GDI Elevation of Privilege Vulnerability | 3.5% | — |
| CVE-2020-24588 | LOW 3.5 | arista c-100_firmware The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU fr | 3.5% | — |
| CVE-2019-0813 | CRIT 9.8 | microsoft windows_admin_center An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'Windows Admin Center Elevation of Privilege Vulnerability'. | 3.5% | — |
| CVE-2021-42284 | MED 6.8 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 3.5% | — |
| CVE-2023-24892 | HIGH 8.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability | 3.5% | — |
| CVE-2019-1318 | MED 5.9 | microsoft windows_10 A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'. | 3.5% | — |