56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1593 | HIGH 7.6 | microsoft windows_10 <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.</p> <p>There are multiple ways an attacker could exp | 2.8% | — |
| CVE-2020-17121 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2026-26130 | HIGH 7.5 | microsoft asp.net_core Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 2.8% | — |
| CVE-1999-1365 | HIGH 7.2 | microsoft windows_nt Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privil | 2.8% | — |
| CVE-2013-4015 | MED 6.9 | microsoft internet_explorer Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed cod | 2.8% | — |
| CVE-2024-28910 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-35841 | HIGH 8.8 | microsoft windows_10 Windows Enterprise App Management Service Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2018-0895 | MED 4.7 | microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl | 2.8% | — |
| CVE-2022-24539 | HIGH 8.1 | microsoft windows_server_2016 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability | 2.8% | — |
| CVE-2021-24101 | MED 6.5 | microsoft dynamics_365 Microsoft Dataverse Information Disclosure Vulnerability | 2.8% | — |
| CVE-2018-8209 | HIGH 8.0 | microsoft windows_10 An information disclosure vulnerability exists when Windows allows a normal user to access the Wireless LAN profile of an administrative user, aka "Windows Wireless Network Profile Information Disclosure Vulnerability." This affects Windows Server 2016, Window | 2.8% | — |
| CVE-2023-36566 | MED 6.5 | microsoft common_data_model_sdk Microsoft Common Data Model SDK Denial of Service Vulnerability | 2.8% | — |
| CVE-2022-26934 | MED 6.5 | microsoft 365_apps Windows Graphics Component Information Disclosure Vulnerability | 2.8% | — |
| CVE-2020-1473 | HIGH 7.0 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 2.8% | — |
| CVE-2015-6112 | MED 5.8 | microsoft windows_7 SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's | 2.8% | — |
| CVE-2021-24100 | MED 5.0 | microsoft edge Microsoft Edge for Android Information Disclosure Vulnerability | 2.8% | — |
| CVE-2021-30611 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30611 Use after free in WebRTC | 2.8% | — |
| CVE-2026-50351 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. | 2.8% | — |
| CVE-2026-49170 | HIGH 7.8 | microsoft windows_10_1809 Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | 2.8% | — |
| CVE-2022-26936 | MED 6.5 | microsoft windows_10 Windows Server Service Information Disclosure Vulnerability | 2.8% | — |
| CVE-2025-47994 | HIGH 7.8 | microsoft 365_apps Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally. | 2.8% | — |
| CVE-2022-24469 | HIGH 8.1 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2022-29107 | MED 5.5 | microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability | 2.8% | — |
| CVE-2020-16910 | MED 6.2 | microsoft windows_10 <p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.</p> <p>To exploit this vulne | 2.8% | — |
| CVE-2019-0654 | MED 4.3 | microsoft edge A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'. | 2.8% | — |