56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1008 | MED 5.9 | microsoft dynamics_365 A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'. | 2.8% | — |
| CVE-2018-0751 | HIGH 7.1 | microsoft windows_10 The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Kernel API enforces | 2.8% | — |
| CVE-2002-1184 | MED 4.6 | microsoft windows_2000 The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain p | 2.8% | — |
| CVE-2024-20661 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.8% | — |
| CVE-2024-0057 | CRIT 9.1 | microsoft .net NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability | 2.8% | — |
| CVE-2020-1182 | HIGH 7.3 | microsoft dynamics_365_for_finance_and_operations A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gain remote code execution via server-side script execution on the | 2.8% | — |
| CVE-2022-29148 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2020-17158 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-17152 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2023-33137 | HIGH 7.8 | microsoft office Microsoft Excel Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2019-1398 | HIGH 8.4 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CV | 2.7% | — |
| CVE-2021-33741 | HIGH 8.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2021-26436 | MED 6.1 | microsoft edge Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2009-0078 | HIGH 7.2 | microsoft windows_server_2003 The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkSe | 2.7% | — |
| CVE-2022-35804 | HIGH 8.8 | microsoft windows_11 SMB Client and Server Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2024-38095 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 2.7% | — |
| CVE-2020-16860 | MED 6.8 | microsoft dynamics_365 <p>A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in | 2.7% | — |
| CVE-2023-21538 | HIGH 7.5 | fedoraproject fedora .NET Denial of Service Vulnerability | 2.7% | — |
| CVE-2022-29105 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-21915 | MED 6.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 2.7% | — |
| CVE-2020-16933 | HIGH 7.0 | microsoft 365_apps <p>A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of | 2.7% | — |
| CVE-2022-29131 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-29129 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-29128 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-1507 | HIGH 7.9 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.</p> <p>To exploit the vulnerabi | 2.7% | — |