IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-1304 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE 3.3%
CVE-2020-1282 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE 3.3%
CVE-2020-16937 MED 4.7 microsoft .net_framework <p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.</p> <p>To exploit the vulnerability 3.3%
CVE-2024-20677 HIGH 7.8 microsoft 365_apps A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feat 3.3%
CVE-2021-31936 HIGH 7.4 microsoft accessibility_insights_for_web Microsoft Accessibility Insights for Web Information Disclosure Vulnerability 3.3%
CVE-2018-8454 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when Windows Audio Service fails to properly handle objects in memory, aka "Windows Audio Service Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019. 3.3%
CVE-2016-7220 LOW 3.3 microsoft windows_10 Virtual Secure Mode in Microsoft Windows 10 allows local users to obtain sensitive information via a crafted application, aka "Virtual Secure Mode Information Disclosure Vulnerability." 3.3%
CVE-2025-27740 HIGH 8.8 microsoft windows_server_2008 Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network. 3.3%
CVE-2022-34724 HIGH 7.5 microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability 3.3%
CVE-2021-24112 HIGH 8.1 microsoft .net .NET Core Remote Code Execution Vulnerability 3.3%
CVE-2022-26924 HIGH 7.5 microsoft yet_another_reverse_proxy YARP Denial of Service Vulnerability 3.3%
CVE-2020-1061 HIGH 7.5 microsoft windows_10 A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attac 3.3%
CVE-2021-36960 HIGH 7.5 microsoft windows_10 Windows SMB Information Disclosure Vulnerability 3.3%
CVE-2020-1112 HIGH 8.5 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content. An attacker who successfully exploited this vulnerability could upload restricted file types to an II 3.3%
CVE-2018-8470 MED 6.1 microsoft internet_explorer A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11. 3.3%
CVE-2020-0908 HIGH 7.5 microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows Text Service Module improperly handles memory. An attacker who successfully exploited the vulnerability could gain execution on a victim system.</p> <p>An attacker could host a specially crafted 3.3%
CVE-2020-1509 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could caus 3.3%
CVE-2020-0692 HIGH 8.1 microsoft exchange_server An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. 3.3%
CVE-2019-1457 HIGH 7.8 microsoft office A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'. 3.3%
CVE-2015-2553 HIGH 7.2 microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles junctions during mountpoint creation, which makes it easie 3.3%
CVE-2017-8551 MED 6.1 microsoft project_server An elevation of privilege vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft SharePoint XSS vulnerability". 3.3%
CVE-2023-35638 HIGH 7.5 microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability 3.3%
CVE-2024-38147 HIGH 7.8 microsoft windows_10_21h2 Microsoft DWM Core Library Elevation of Privilege Vulnerability 3.3%
CVE-2015-6171 HIGH 7.2 microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted app 3.3%
CVE-2008-4510 MED 4.9 microsoft windows_vista Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page fault and system crash) via multiple attempts to access a virtual address in a PAGE_NOACCESS memory page. 3.3%