56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-0985 | HIGH 7.8 | microsoft windows_7 A remote code execution vulnerability exists when the Microsoft Speech API (SAPI) improperly handles text-to-speech (TTS) input. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current us | 3.5% | — |
| CVE-2021-33764 | MED 5.9 | microsoft windows_server_2008 Windows Key Distribution Center Information Disclosure Vulnerability | 3.5% | — |
| CVE-2009-3275 | MED 5.0 | microsoft enterprise_library Blocks/Common/Src/Configuration/Manageability/Adm/AdmContentBuilder.cs in Microsoft patterns & practices Enterprise Library (aka EntLib) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many \ (b | 3.5% | — |
| CVE-2020-17118 | HIGH 8.1 | microsoft sharepoint_foundation Microsoft SharePoint Remote Code Execution Vulnerability | 3.5% | — |
| CVE-1999-1084 | MED 4.6 | microsoft windows_nt The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash. | 3.5% | — |
| CVE-2022-41099 | MED 4.6 | microsoft windows_10 BitLocker Security Feature Bypass Vulnerability | 3.5% | — |
| CVE-2018-0974 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." T | 3.5% | — |
| CVE-2018-0973 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." T | 3.5% | — |
| CVE-2018-0972 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." T | 3.5% | — |
| CVE-2018-0971 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." T | 3.5% | — |
| CVE-2018-0970 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." T | 3.5% | — |
| CVE-2018-0969 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass, aka "Windows Kernel Information Disclosure Vulnerability." T | 3.5% | — |
| CVE-2026-50343 | HIGH 7.8 | microsoft windows_10_1809 Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally. | 3.5% | — |
| CVE-2022-21904 | HIGH 7.5 | microsoft windows_10 Windows GDI Information Disclosure Vulnerability | 3.5% | — |
| CVE-2024-38021 | HIGH 8.8 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 3.5% | — |
| CVE-2025-49741 | HIGH 7.4 | microsoft edge_chromium No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 3.5% | — |
| CVE-2018-8434 | MED 5.4 | microsoft windows_10 An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Information Disclosure Vulnerability." This affects Win | 3.5% | — |
| CVE-2017-11863 | MED 6.1 | microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to trick a user into loading a page containing malicious content, due to how the Edge Content Security Policy (CSP) val | 3.5% | — |
| CVE-2018-8425 | MED 4.3 | microsoft edge A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. | 3.5% | — |
| CVE-2001-1518 | LOW 2.1 | microsoft windows_2000 RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the vendor | 3.5% | — |
| CVE-2017-8719 | MED 4.7 | microsoft windows_10 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabi | 3.5% | — |
| CVE-2017-8709 | MED 4.7 | microsoft windows_10 The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerabi | 3.5% | — |
| CVE-2021-24090 | HIGH 7.8 | microsoft windows_10 Windows Error Reporting Elevation of Privilege Vulnerability | 3.5% | — |
| CVE-2020-16955 | HIGH 7.8 | microsoft 365_apps <p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges.</p> <p>To exploit this vulnerability, an atta | 3.5% | — |
| CVE-2017-8713 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an auth | 3.5% | — |