IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-23415 CRIT 9.8 microsoft windows_10_1507 Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability 3.5%
CVE-2015-1722 HIGH 7.2 microsoft windows_7 Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 3.5%
CVE-2020-0654 CRIT 9.1 microsoft onedrive A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to bypass the passcode or fingerprint requirements of the App.The security update addresses the vulnerability by correcting the way Microsoft OneD 3.5%
CVE-2021-36933 HIGH 7.5 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability 3.5%
CVE-2021-36932 HIGH 7.5 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability 3.5%
CVE-2021-36926 HIGH 7.5 microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability 3.5%
CVE-2001-1519 LOW 3.6 microsoft windows_2000 RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that administrati 3.5%
CVE-2021-30621 MED 6.5 fedoraproject fedora Chromium: CVE-2021-30621 UI Spoofing in Autofill 3.5%
CVE-2021-30619 MED 6.5 fedoraproject fedora Chromium: CVE-2021-30619 UI Spoofing in Autofill 3.5%
CVE-2009-5159 MED 6.1 invisioncommunity invision_power_board Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment. 3.5%
CVE-2021-1679 MED 6.5 microsoft windows_10 Windows CryptoAPI Denial of Service Vulnerability 3.5%
CVE-2018-8512 MED 5.4 microsoft edge A security feature bypass vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge 3.5%
CVE-2021-26885 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 3.5%
CVE-2015-2524 HIGH 7.2 microsoft windows_10 Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Eleva 3.5%
CVE-2015-2366 HIGH 7.2 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elev 3.5%
CVE-2015-2365 HIGH 7.2 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users 3.5%
CVE-2020-1554 HIGH 7.8 microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri 3.5%
CVE-2020-1492 HIGH 7.8 microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri 3.5%
CVE-2025-47732 HIGH 8.7 microsoft dataverse Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. 3.5%
CVE-2022-26825 HIGH 7.2 microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability 3.5%
CVE-2022-26811 HIGH 7.2 microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability 3.5%
CVE-2021-34444 MED 6.5 microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability 3.5%
CVE-2017-0214 HIGH 7.0 microsoft windows_10 Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when Windows fa 3.5%
CVE-2016-7218 MED 4.7 microsoft windows_10 Bowser.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users t 3.5%
CVE-2017-8754 MED 4.2 microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page containing malicious content, due to the way that the Edge Content Security Policy (CSP) validates certain specially c 3.5%