IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2004-2091 MED 5.0 microsoft baseline_security_analyzer Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security. 3.2%
CVE-2023-24871 HIGH 8.8 microsoft windows_10_20h2 Windows Bluetooth Service Remote Code Execution Vulnerability 3.2%
CVE-2020-8927 MED 5.3 canonical ubuntu_linux A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is 3.2%
CVE-2012-2519 HIGH 7.9 microsoft .net_framework Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a dire 3.2%
CVE-2018-0749 HIGH 7.8 microsoft windows_10 The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an 3.2%
CVE-2020-17129 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 3.2%
CVE-2020-17127 HIGH 7.8 microsoft excel Microsoft Excel Remote Code Execution Vulnerability 3.2%
CVE-2020-17125 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 3.2%
CVE-2020-17124 HIGH 7.8 microsoft 365_apps Microsoft PowerPoint Remote Code Execution Vulnerability 3.2%
CVE-2022-34720 HIGH 7.5 microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 3.2%
CVE-2024-29053 HIGH 8.8 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 3.2%
CVE-2024-21323 HIGH 8.8 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 3.2%
CVE-2020-17016 HIGH 8.0 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 3.2%
CVE-2022-21989 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 3.2%
CVE-2022-34700 HIGH 8.8 microsoft dynamics_365 Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability 3.2%
CVE-2021-36929 MED 6.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability 3.2%
CVE-2001-0015 HIGH 7.2 microsoft windows_2000 Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process. 3.2%
CVE-2018-8448 MED 5.4 microsoft exchange_server An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. 3.2%
CVE-2021-31977 HIGH 8.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 3.2%
CVE-2021-31968 HIGH 7.5 microsoft windows_10 Windows Remote Desktop Services Denial of Service Vulnerability 3.2%
CVE-2026-25187 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. 3.2%
CVE-2020-1241 HIGH 7.8 microsoft windows_10 A security feature bypass vulnerability exists when Windows Kernel fails to properly sanitize certain parameters.To exploit the vulnerability, a locally-authenticated attacker could attempt to run a specially crafted application on a targeted system.The update 3.2%
CVE-2018-8565 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka "Win32k Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Ser 3.2%
CVE-2026-62696 HIGH 7.8 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. 3.2%
CVE-2026-50509 HIGH 7.8 microsoft windows_10_1607 Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally. 3.2%