56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1305 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'. | 3.1% | — |
| CVE-2019-1425 | MED 6.5 | microsoft visual_studio_2017 An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'. | 3.1% | — |
| CVE-2023-23382 | MED 6.5 | microsoft azure_machine_learning Azure Machine Learning Compute Instance Information Disclosure Vulnerability | 3.1% | — |
| CVE-2021-33755 | MED 6.3 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 3.1% | — |
| CVE-2020-1568 | HIGH 7.5 | microsoft edge A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An att | 3.1% | — |
| CVE-2023-48692 | CRIT 9.0 | microsoft azure_rtos_netx_duo Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include p | 3.1% | — |
| CVE-2023-48691 | HIGH 8.1 | microsoft azure_rtos_netx_duo Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause an out-of-bounds write in Azure RTOS NETX Duo, that could lead to remote code execution. The affected components inclu | 3.1% | — |
| CVE-2018-8449 | LOW 3.3 | microsoft windows_10 A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | 3.1% | — |
| CVE-2015-6174 | HIGH 7.2 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted app | 3.1% | — |
| CVE-2015-6173 | HIGH 7.2 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted app | 3.1% | — |
| CVE-2015-6101 | MED 6.9 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted app | 3.1% | — |
| CVE-2018-0826 | HIGH 7.0 | microsoft windows_10 Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Storage Services Elevation | 3.1% | — |
| CVE-2024-20666 | MED 6.6 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 3.1% | — |
| CVE-2019-1187 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker who successfully exploited this vulnerability could cause a denial of service against an XML application. A remote unauthenticated attacker | 3.1% | — |
| CVE-2022-21840 | HIGH 8.8 | microsoft excel Microsoft Office Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2021-1714 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2021-1713 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2017-0051 | MED 5.4 | microsoft windows_10 Microsoft Windows 10 1607 and Windows Server 2016 allow remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Hyper-V Network Switch Denial of Service Vulnerability." This vulnerability is different from | 3.1% | — |
| CVE-2020-1092 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who su | 3.1% | — |
| CVE-2020-1060 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who s | 3.1% | — |
| CVE-2020-1058 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who s | 3.1% | — |
| CVE-2026-33112 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 3.1% | — |
| CVE-2022-24490 | HIGH 8.1 | microsoft windows_server_2016 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability | 3.1% | — |
| CVE-2020-17079 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2021-42306 | HIGH 8.1 | microsoft azure_active_directory An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulner | 3.1% | — |