56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-26859 | HIGH 7.7 | microsoft power_bi_report_server Microsoft Power BI Information Disclosure Vulnerability | 3.0% | — |
| CVE-2017-8685 | MED 5.5 | microsoft windows_7 Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8684 and | 3.0% | — |
| CVE-2019-0941 | MED 4.4 | microsoft windows_10 A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests. An attacker who successfully exploited this vulnerability could perform a temporary denial of service against pages configured to use re | 3.0% | — |
| CVE-2025-59501 | MED 4.8 | microsoft configuration_manager_2403 Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network. | 3.0% | — |
| CVE-2021-27066 | MED 4.3 | microsoft windows_admin_center Windows Admin Center Security Feature Bypass Vulnerability | 3.0% | — |
| CVE-2021-21133 | MED 6.5 | google chrome Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a user to download files to bypass navigation restrictions via a crafted HTML page. | 3.0% | — |
| CVE-2019-1345 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1334. | 3.0% | — |
| CVE-2022-38034 | HIGH 8.8 | microsoft windows_10 Windows Workstation Service Elevation of Privilege Vulnerability | 3.0% | — |
| CVE-2019-0959 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vuln | 3.0% | — |
| CVE-2018-0785 | MED 6.5 | microsoft asp.net_core ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability". | 3.0% | — |
| CVE-2016-0090 | HIGH 7.1 | microsoft windows_10 Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka "Hyper-V Information Disclosure Vulnerability." | 3.0% | — |
| CVE-2026-26114 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 3.0% | — |
| CVE-2022-21890 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 3.0% | — |
| CVE-2022-21889 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 3.0% | — |
| CVE-2026-66804 | HIGH 7.8 | microsoft windows_10_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | 3.0% | — |
| CVE-2019-1043 | MED 6.4 | microsoft windows_10 A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successf | 3.0% | — |
| CVE-2020-1314 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server fails to properly handle messages sent from TSF clients, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'. | 3.0% | — |
| CVE-2020-1291 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. | 3.0% | — |
| CVE-2020-1287 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1294. | 3.0% | — |
| CVE-2020-1280 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Bluetooth Service handles objects in memory, aka 'Windows Bluetooth Service Elevation of Privilege Vulnerability'. | 3.0% | — |
| CVE-2020-1211 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. | 3.0% | — |
| CVE-2009-2057 | MED 5.8 | microsoft ie Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying t | 3.0% | — |
| CVE-2017-8514 | MED 5.4 | microsoft sharepoint_enterprise_server An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft SharePoint Reflective XSS Vulnerability". | 3.0% | — |
| CVE-2020-1244 | HIGH 7.1 | microsoft windows_10 A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1120. | 3.0% | — |
| CVE-2018-8374 | MED 4.3 | microsoft exchange_server A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server. | 3.0% | — |