IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-21837 HIGH 8.3 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 3.0%
CVE-2019-0875 HIGH 7.5 microsoft azure_devops_server An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissions, aka 'Azure DevOps Server Elevation of Privilege Vulnerability'. 3.0%
CVE-2016-7246 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted applicatio 3.0%
CVE-2016-7215 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileg 3.0%
CVE-2011-1971 MED 4.7 microsoft windows_7 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse file metadata, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Metadat 3.0%
CVE-2017-11785 MED 5.5 microsoft windows_10 The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an information disclosur 3.0%
CVE-2017-8564 MED 5.5 microsoft windows_10 Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it f 3.0%
CVE-2025-21219 MED 4.3 microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability 3.0%
CVE-2016-4158 HIGH 7.3 adobe creative_cloud Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory. 3.0%
CVE-2016-7211 HIGH 7.3 microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl 3.0%
CVE-2018-8127 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 3.0%
CVE-2023-35383 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability 3.0%
CVE-2023-28285 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 3.0%
CVE-2021-1656 MED 5.5 microsoft windows_10 TPM Device Driver Information Disclosure Vulnerability 3.0%
CVE-2026-25667 HIGH 7.5 microsoft .net ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processin 3.0%
CVE-2001-0006 HIGH 7.1 microsoft windows_nt The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Wins 3.0%
CVE-2020-1235 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1265, CVE-2020-1282, CVE 3.0%
CVE-2021-43888 HIGH 7.5 microsoft defender_for_iot Microsoft Defender for IoT Information Disclosure Vulnerability 3.0%
CVE-2021-43236 HIGH 7.5 microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability 3.0%
CVE-2021-43222 HIGH 7.5 microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability 3.0%
CVE-2019-0570 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windows Runtime Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2 3.0%
CVE-2019-1262 MED 5.4 microsoft sharepoint_foundation A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. 3.0%
CVE-2022-24492 HIGH 8.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 3.0%
CVE-2021-1710 HIGH 7.8 microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 3.0%
CVE-2020-1569 HIGH 7.8 microsoft edge A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who 3.0%