56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2004-2091 | MED 5.0 | microsoft baseline_security_analyzer Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security. | 3.2% | — |
| CVE-2023-24871 | HIGH 8.8 | microsoft windows_10_20h2 Windows Bluetooth Service Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2020-8927 | MED 5.3 | canonical ubuntu_linux A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is | 3.2% | — |
| CVE-2012-2519 | HIGH 7.9 | microsoft .net_framework Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a dire | 3.2% | — |
| CVE-2018-0749 | HIGH 7.8 | microsoft windows_10 The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an | 3.2% | — |
| CVE-2020-17129 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2020-17127 | HIGH 7.8 | microsoft excel Microsoft Excel Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2020-17125 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2020-17124 | HIGH 7.8 | microsoft 365_apps Microsoft PowerPoint Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2022-34720 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 3.2% | — |
| CVE-2024-29053 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2024-21323 | HIGH 8.8 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2020-17016 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 3.2% | — |
| CVE-2022-21989 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 3.2% | — |
| CVE-2022-34700 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2021-36929 | MED 6.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 3.2% | — |
| CVE-2001-0015 | HIGH 7.2 | microsoft windows_2000 Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process. | 3.2% | — |
| CVE-2018-8448 | MED 5.4 | microsoft exchange_server An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. | 3.2% | — |
| CVE-2021-31977 | HIGH 8.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 3.2% | — |
| CVE-2021-31968 | HIGH 7.5 | microsoft windows_10 Windows Remote Desktop Services Denial of Service Vulnerability | 3.2% | — |
| CVE-2026-25187 | HIGH 7.8 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. | 3.2% | — |
| CVE-2020-1241 | HIGH 7.8 | microsoft windows_10 A security feature bypass vulnerability exists when Windows Kernel fails to properly sanitize certain parameters.To exploit the vulnerability, a locally-authenticated attacker could attempt to run a specially crafted application on a targeted system.The update | 3.2% | — |
| CVE-2018-8565 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka "Win32k Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Ser | 3.2% | — |
| CVE-2026-62696 | HIGH 7.8 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. | 3.2% | — |
| CVE-2026-50509 | HIGH 7.8 | microsoft windows_10_1607 Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. | 3.2% | — |