56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2002-0151 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request. | 3.3% | — |
| CVE-2020-1508 | HIGH 7.6 | microsoft windows_10 <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.</p> <p>There are multiple ways an attacker could exp | 3.3% | — |
| CVE-2021-34490 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-34476 | HIGH 7.5 | microsoft windows_10 Bowser.sys Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-33788 | HIGH 7.5 | microsoft windows_10 Windows LSA Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-33785 | HIGH 7.5 | microsoft windows_10 Windows AF_UNIX Socket Provider Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-33772 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 3.3% | — |
| CVE-2017-8544 | MED 5.5 | microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to obtain information to further compromise the user's sys | 3.3% | — |
| CVE-2022-38013 | HIGH 7.5 | fedoraproject fedora .NET Core and Visual Studio Denial of Service Vulnerability | 3.2% | — |
| CVE-2021-1694 | HIGH 7.5 | microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability | 3.2% | — |
| CVE-2020-1150 | HIGH 7.8 | microsoft windows_7 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 3.2% | — |
| CVE-1999-0468 | HIGH 8.2 | microsoft internet_explorer Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component. | 3.2% | — |
| CVE-2021-43216 | MED 6.5 | microsoft windows_10 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | 3.2% | — |
| CVE-2020-17122 | HIGH 7.8 | microsoft office Microsoft Excel Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2026-24291 | HIGH 7.8 | microsoft windows_10_1607 Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. | 3.2% | — |
| CVE-2025-21247 | MED 4.3 | microsoft windows_10_1507 Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | 3.2% | — |
| CVE-1999-0861 | LOW 2.6 | microsoft commercial_internet_system Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. | 3.2% | — |
| CVE-2026-21238 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 3.2% | — |
| CVE-2020-17002 | HIGH 7.4 | microsoft c_sdk_for_azure_iot Azure SDK for C Security Feature Bypass Vulnerability | 3.2% | — |
| CVE-1999-0899 | HIGH 7.2 | microsoft windows_nt The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider. | 3.2% | — |
| CVE-2015-6100 | MED 6.9 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted app | 3.2% | — |
| CVE-2021-34507 | MED 6.5 | microsoft windows_10 Windows Remote Assistance Information Disclosure Vulnerability | 3.2% | — |
| CVE-2018-0961 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packet data, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | 3.2% | — |
| CVE-2016-3218 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application | 3.2% | — |
| CVE-2005-3169 | MED 5.0 | microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4, when the "audit directory service access" policy is enabled, does not record a 565 event message for File Delete Child operations on an Active Directory object in the security event log, which could allow | 3.2% | — |