56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-0805 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0836, CVE | 2.8% | — |
| CVE-2023-35349 | CRIT 9.8 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-21851 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-21850 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2018-8446 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 2.8% | — |
| CVE-2018-8445 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8336, CVE-2 | 2.8% | — |
| CVE-2018-8443 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 2.8% | — |
| CVE-2018-8442 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 2.8% | — |
| CVE-2018-8336 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique f | 2.8% | — |
| CVE-2018-8271 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in Windows when the Windows bowser.sys kernel-mode driver fails to properly handle objects in memory, aka "Windows Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT | 2.8% | — |
| CVE-2022-34701 | HIGH 7.5 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability | 2.8% | — |
| CVE-2022-24548 | MED 5.5 | microsoft malware_protection_engine Microsoft Defender Denial of Service Vulnerability | 2.8% | — |
| CVE-2023-36038 | HIGH 8.2 | microsoft asp.net_core ASP.NET Core Denial of Service Vulnerability | 2.8% | — |
| CVE-2021-31944 | MED 5.0 | microsoft 3d_viewer 3D Viewer Information Disclosure Vulnerability | 2.8% | — |
| CVE-2022-23259 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2018-0752 | HIGH 7.8 | microsoft windows_10 The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Kernel API enforces | 2.8% | — |
| CVE-2018-0748 | HIGH 7.8 | microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulne | 2.8% | — |
| CVE-2025-54098 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 2.8% | — |
| CVE-2022-21922 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-21920 | HIGH 8.8 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2021-30612 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30612 Use after free in WebRTC | 2.8% | — |
| CVE-2021-24084 | MED 5.5 | microsoft windows_10 Windows Mobile Device Management Information Disclosure Vulnerability | 2.8% | — |
| CVE-2021-33783 | MED 6.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 2.8% | — |
| CVE-2021-43225 | HIGH 7.5 | microsoft bot_framework_software_development_kit Bot Framework SDK Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2013-5058 | MED 6.9 | microsoft windows_7 Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to ga | 2.8% | — |