56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-21837 | HIGH 8.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2019-0875 | HIGH 7.5 | microsoft azure_devops_server An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissions, aka 'Azure DevOps Server Elevation of Privilege Vulnerability'. | 3.0% | — |
| CVE-2016-7246 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted applicatio | 3.0% | — |
| CVE-2016-7215 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileg | 3.0% | — |
| CVE-2011-1971 | MED 4.7 | microsoft windows_7 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse file metadata, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Metadat | 3.0% | — |
| CVE-2017-11785 | MED 5.5 | microsoft windows_10 The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an information disclosur | 3.0% | — |
| CVE-2017-8564 | MED 5.5 | microsoft windows_10 Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it f | 3.0% | — |
| CVE-2025-21219 | MED 4.3 | microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability | 3.0% | — |
| CVE-2016-4158 | HIGH 7.3 | adobe creative_cloud Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory. | 3.0% | — |
| CVE-2016-7211 | HIGH 7.3 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl | 3.0% | — |
| CVE-2018-8127 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows | 3.0% | — |
| CVE-2023-35383 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability | 3.0% | — |
| CVE-2023-28285 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2021-1656 | MED 5.5 | microsoft windows_10 TPM Device Driver Information Disclosure Vulnerability | 3.0% | — |
| CVE-2026-25667 | HIGH 7.5 | microsoft .net ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processin | 3.0% | — |
| CVE-2001-0006 | HIGH 7.1 | microsoft windows_nt The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Wins | 3.0% | — |
| CVE-2020-1235 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1265, CVE-2020-1282, CVE | 3.0% | — |
| CVE-2021-43888 | HIGH 7.5 | microsoft defender_for_iot Microsoft Defender for IoT Information Disclosure Vulnerability | 3.0% | — |
| CVE-2021-43236 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability | 3.0% | — |
| CVE-2021-43222 | HIGH 7.5 | microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability | 3.0% | — |
| CVE-2019-0570 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windows Runtime Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2 | 3.0% | — |
| CVE-2019-1262 | MED 5.4 | microsoft sharepoint_foundation A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. | 3.0% | — |
| CVE-2022-24492 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2021-1710 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2020-1569 | HIGH 7.8 | microsoft edge A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who | 3.0% | — |