56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-0241 | MED 5.3 | microsoft edge An elevation of privilege vulnerability exists when Microsoft Edge renders a domain-less page in the URL, which could allow Microsoft Edge to perform actions in the context of the Intranet Zone and access functionality that is not typically available to the br | 2.9% | — |
| CVE-2018-0745 | MED 4.7 | microsoft windows_10 The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Information Disclosure Vulnerability". This CVE I | 2.9% | — |
| CVE-2023-29324 | MED 6.5 | microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability | 2.9% | — |
| CVE-2023-28293 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2020-17120 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Information Disclosure Vulnerability | 2.9% | — |
| CVE-2018-0882 | HIGH 7.0 | microsoft windows_10 The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerabil | 2.9% | — |
| CVE-2021-24080 | MED 6.5 | microsoft windows_10 Windows Trust Verification API Denial of Service Vulnerability | 2.9% | — |
| CVE-2021-43892 | HIGH 7.4 | microsoft biztalk_esb_toolkit Microsoft BizTalk ESB Toolkit Spoofing Vulnerability | 2.9% | — |
| CVE-2018-8235 | MED 4.3 | microsoft edge A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge. | 2.9% | — |
| CVE-2017-11850 | LOW 2.5 | microsoft windows_10 Microsoft Graphics Component in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to log on to an affected system and run a specially crafted | 2.9% | — |
| CVE-2020-17055 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2020-17044 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2020-17043 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2020-1525 | HIGH 7.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri | 2.9% | — |
| CVE-2004-2176 | MED 4.6 | microsoft windows_xp The Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which allows local users to use sessmgr.exe to create a local listening port that bypasses the ICF access controls. | 2.8% | — |
| CVE-2022-24515 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2023-21744 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2021-34499 | MED 6.5 | microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability | 2.8% | — |
| CVE-2021-33758 | HIGH 7.7 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 2.8% | — |
| CVE-2021-33745 | MED 6.5 | microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability | 2.8% | — |
| CVE-2021-24114 | MED 5.7 | microsoft teams Microsoft Teams iOS Information Disclosure Vulnerability | 2.8% | — |
| CVE-2000-1088 | MED 4.6 | microsoft data_engine The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows | 2.8% | — |
| CVE-2018-0743 | HIGH 7.0 | microsoft windows_10 Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Subsystem for Linux Elevation of Privile | 2.8% | — |
| CVE-2021-26867 | CRIT 9.9 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2020-0890 | MED 6.5 | microsoft windows_10 <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.</p> <p>To exploit the vulnerability, an attacker who already has a privileged accoun | 2.8% | — |