56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-17053 | HIGH 7.5 | microsoft internet_explorer Internet Explorer Memory Corruption Vulnerability | 3.2% | — |
| CVE-2025-27738 | MED 6.5 | microsoft windows_10_1507 Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network. | 3.2% | — |
| CVE-2017-8621 | MED 6.1 | microsoft exchange_server Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnerability that could lead to spoofing, aka "Microsoft Exchange Open Redirect Vulnerability". | 3.2% | — |
| CVE-2020-1563 | HIGH 7.8 | microsoft 365_apps A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the | 3.2% | — |
| CVE-2022-23284 | HIGH 7.2 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 3.2% | — |
| CVE-2020-17078 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2025-29972 | CRIT 9.9 | microsoft azure_storage_resource_provider Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. | 3.2% | — |
| CVE-2021-24091 | HIGH 7.8 | microsoft windows_10 Windows Camera Codec Pack Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2025-55692 | HIGH 7.8 | microsoft windows_10_1507 Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | 3.2% | — |
| CVE-2020-1292 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in OpenSSH for Windows when it does not properly restrict access to configuration settings, aka 'OpenSSH for Windows Elevation of Privilege Vulnerability'. | 3.2% | — |
| CVE-2020-1237 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2 | 3.2% | — |
| CVE-2024-43582 | HIGH 8.1 | microsoft windows_10_1809 Remote Desktop Protocol Server Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2021-31175 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2021-27060 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2024-20696 | HIGH 7.3 | microsoft windows_10_1809 Windows libarchive Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2021-40448 | MED 6.3 | microsoft accessibility_insights_for_android Microsoft Accessibility Insights for Android Information Disclosure Vulnerability | 3.2% | — |
| CVE-2018-8208 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. Th | 3.2% | — |
| CVE-2025-24076 | HIGH 7.3 | microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | 3.2% | — |
| CVE-2003-0004 | HIGH 7.2 | microsoft windows_xp Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code via a long parameter. | 3.1% | — |
| CVE-2017-0181 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10 or Windows Server 2016 host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execut | 3.1% | — |
| CVE-2017-0163 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is | 3.1% | — |
| CVE-2017-0162 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from an authenticated user on a guest operating s | 3.1% | — |
| CVE-2002-2105 | LOW 2.1 | microsoft windows_xp Microsoft Windows XP allows local users to prevent the system from booting via a corrupt explorer.exe.manifest file. | 3.1% | — |
| CVE-2021-34442 | HIGH 8.8 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2010-0482 | MED 4.7 | microsoft windows_7 The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Malformed Image Vulnerability." | 3.1% | — |