IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-26197 MED 6.5 microsoft windows_server_2012 Windows Standards-Based Storage Management Service Denial of Service Vulnerability 2.8%
CVE-2023-36028 CRIT 9.8 microsoft windows_10_1507 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability 2.8%
CVE-2000-1087 MED 4.6 microsoft data_engine The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allow 2.8%
CVE-2000-1086 MED 4.6 microsoft data_engine The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allow 2.8%
CVE-2000-1084 MED 4.6 microsoft data_engine The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an att 2.8%
CVE-2000-1082 MED 4.6 microsoft data_engine The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an at 2.8%
CVE-2024-49096 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.8%
CVE-2021-41356 HIGH 7.5 microsoft windows_10 Windows Denial of Service Vulnerability 2.8%
CVE-2019-1153 MED 5.5 microsoft office An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exp 2.8%
CVE-2019-1148 MED 5.5 microsoft office An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exp 2.8%
CVE-2000-0100 HIGH 7.2 microsoft systems_management_server The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program. 2.8%
CVE-2023-29332 HIGH 7.5 microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 2.8%
CVE-2022-23265 HIGH 7.2 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 2.8%
CVE-2022-41038 HIGH 8.8 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 2.8%
CVE-2009-1808 MED 4.9 microsoft windows_xp Microsoft Windows XP SP3 allows local users to cause a denial of service (system crash) by making an SPI_SETDESKWALLPAPER SystemParametersInfo call with an improperly terminated pvParam argument, followed by an SPI_GETDESKWALLPAPER SystemParametersInfo call. 2.8%
CVE-2021-42293 MED 6.5 microsoft 365_apps Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability 2.8%
CVE-2025-55694 HIGH 7.8 microsoft windows_11_24h2 Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally. 2.8%
CVE-2022-24519 MED 6.5 microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability 2.8%
CVE-2022-24518 MED 6.5 microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability 2.8%
CVE-2022-24506 MED 6.5 microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability 2.8%
CVE-2021-34453 HIGH 7.5 microsoft exchange_server Microsoft Exchange Server Denial of Service Vulnerability 2.8%
CVE-2020-1343 MED 5.9 microsoft visual_studio_live_share An information disclosure vulnerability exists in Visual Studio Code Live Share Extension when it exposes tokens in plain text, aka 'Visual Studio Code Live Share Information Disclosure Vulnerability'. 2.8%
CVE-2002-0366 HIGH 7.2 microsoft windows_2000 Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry. 2.8%
CVE-2023-36003 MED 6.7 microsoft windows_10_1507 XAML Diagnostics Elevation of Privilege Vulnerability 2.8%
CVE-2021-43905 CRIT 9.6 microsoft 365_copilot Microsoft Office app Remote Code Execution Vulnerability 2.8%