IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-1593 HIGH 7.6 microsoft windows_10 <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.</p> <p>There are multiple ways an attacker could exp 2.8%
CVE-2020-17121 HIGH 8.8 microsoft sharepoint_foundation Microsoft SharePoint Remote Code Execution Vulnerability 2.8%
CVE-2026-26130 HIGH 7.5 microsoft asp.net_core Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. 2.8%
CVE-1999-1365 HIGH 7.2 microsoft windows_nt Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privil 2.8%
CVE-2013-4015 MED 6.9 microsoft internet_explorer Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed cod 2.8%
CVE-2024-28910 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.8%
CVE-2022-35841 HIGH 8.8 microsoft windows_10 Windows Enterprise App Management Service Remote Code Execution Vulnerability 2.8%
CVE-2018-0895 MED 4.7 microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl 2.8%
CVE-2022-24539 HIGH 8.1 microsoft windows_server_2016 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability 2.8%
CVE-2021-24101 MED 6.5 microsoft dynamics_365 Microsoft Dataverse Information Disclosure Vulnerability 2.8%
CVE-2018-8209 HIGH 8.0 microsoft windows_10 An information disclosure vulnerability exists when Windows allows a normal user to access the Wireless LAN profile of an administrative user, aka "Windows Wireless Network Profile Information Disclosure Vulnerability." This affects Windows Server 2016, Window 2.8%
CVE-2023-36566 MED 6.5 microsoft common_data_model_sdk Microsoft Common Data Model SDK Denial of Service Vulnerability 2.8%
CVE-2022-26934 MED 6.5 microsoft 365_apps Windows Graphics Component Information Disclosure Vulnerability 2.8%
CVE-2020-1473 HIGH 7.0 microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu 2.8%
CVE-2015-6112 MED 5.8 microsoft windows_7 SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's 2.8%
CVE-2021-24100 MED 5.0 microsoft edge Microsoft Edge for Android Information Disclosure Vulnerability 2.8%
CVE-2021-30611 HIGH 8.8 fedoraproject fedora Chromium: CVE-2021-30611 Use after free in WebRTC 2.8%
CVE-2026-50351 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally. 2.8%
CVE-2026-49170 HIGH 7.8 microsoft windows_10_1809 Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. 2.8%
CVE-2022-26936 MED 6.5 microsoft windows_10 Windows Server Service Information Disclosure Vulnerability 2.8%
CVE-2025-47994 HIGH 7.8 microsoft 365_apps Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally. 2.8%
CVE-2022-24469 HIGH 8.1 microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability 2.8%
CVE-2022-29107 MED 5.5 microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability 2.8%
CVE-2020-16910 MED 6.2 microsoft windows_10 <p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.</p> <p>To exploit this vulne 2.8%
CVE-2019-0654 MED 4.3 microsoft edge A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'. 2.8%