IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-26859 HIGH 7.7 microsoft power_bi_report_server Microsoft Power BI Information Disclosure Vulnerability 3.0%
CVE-2017-8685 MED 5.5 microsoft windows_7 Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8684 and 3.0%
CVE-2019-0941 MED 4.4 microsoft windows_10 A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests. An attacker who successfully exploited this vulnerability could perform a temporary denial of service against pages configured to use re 3.0%
CVE-2025-59501 MED 4.8 microsoft configuration_manager_2403 Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network. 3.0%
CVE-2021-27066 MED 4.3 microsoft windows_admin_center Windows Admin Center Security Feature Bypass Vulnerability 3.0%
CVE-2021-21133 MED 6.5 google chrome Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a user to download files to bypass navigation restrictions via a crafted HTML page. 3.0%
CVE-2019-1345 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1334. 3.0%
CVE-2022-38034 HIGH 8.8 microsoft windows_10 Windows Workstation Service Elevation of Privilege Vulnerability 3.0%
CVE-2019-0959 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vuln 3.0%
CVE-2018-0785 MED 6.5 microsoft asp.net_core ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability". 3.0%
CVE-2016-0090 HIGH 7.1 microsoft windows_10 Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka "Hyper-V Information Disclosure Vulnerability." 3.0%
CVE-2026-26114 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 3.0%
CVE-2022-21890 HIGH 7.5 microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 3.0%
CVE-2022-21889 HIGH 7.5 microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability 3.0%
CVE-2026-66804 HIGH 7.8 microsoft windows_10_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. 3.0%
CVE-2019-1043 MED 6.4 microsoft windows_10 A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successf 3.0%
CVE-2020-1314 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server fails to properly handle messages sent from TSF clients, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'. 3.0%
CVE-2020-1291 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. 3.0%
CVE-2020-1287 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1294. 3.0%
CVE-2020-1280 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Bluetooth Service handles objects in memory, aka 'Windows Bluetooth Service Elevation of Privilege Vulnerability'. 3.0%
CVE-2020-1211 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. 3.0%
CVE-2009-2057 MED 5.8 microsoft ie Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying t 3.0%
CVE-2017-8514 MED 5.4 microsoft sharepoint_enterprise_server An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft SharePoint Reflective XSS Vulnerability". 3.0%
CVE-2020-1244 HIGH 7.1 microsoft windows_10 A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1120. 3.0%
CVE-2018-8374 MED 4.3 microsoft exchange_server A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server. 3.0%