IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1008 MED 5.9 microsoft dynamics_365 A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'. 2.8%
CVE-2018-0751 HIGH 7.1 microsoft windows_10 The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Kernel API enforces 2.8%
CVE-2002-1184 MED 4.6 microsoft windows_2000 The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain p 2.8%
CVE-2024-20661 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.8%
CVE-2024-0057 CRIT 9.1 microsoft .net NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability 2.8%
CVE-2020-1182 HIGH 7.3 microsoft dynamics_365_for_finance_and_operations A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gain remote code execution via server-side script execution on the 2.8%
CVE-2022-29148 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability 2.8%
CVE-2020-17158 HIGH 8.8 microsoft dynamics_365 Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability 2.7%
CVE-2020-17152 HIGH 8.8 microsoft dynamics_365 Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability 2.7%
CVE-2023-33137 HIGH 7.8 microsoft office Microsoft Excel Remote Code Execution Vulnerability 2.7%
CVE-2019-1398 HIGH 8.4 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CV 2.7%
CVE-2021-33741 HIGH 8.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 2.7%
CVE-2021-26436 MED 6.1 microsoft edge Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 2.7%
CVE-2009-0078 HIGH 7.2 microsoft windows_server_2003 The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkSe 2.7%
CVE-2022-35804 HIGH 8.8 microsoft windows_11 SMB Client and Server Remote Code Execution Vulnerability 2.7%
CVE-2024-38095 HIGH 7.5 microsoft .net .NET and Visual Studio Denial of Service Vulnerability 2.7%
CVE-2020-16860 MED 6.8 microsoft dynamics_365 <p>A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in 2.7%
CVE-2023-21538 HIGH 7.5 fedoraproject fedora .NET Denial of Service Vulnerability 2.7%
CVE-2022-29105 HIGH 7.8 microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 2.7%
CVE-2022-21915 MED 6.5 microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability 2.7%
CVE-2020-16933 HIGH 7.0 microsoft 365_apps <p>A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of 2.7%
CVE-2022-29131 HIGH 8.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.7%
CVE-2022-29129 HIGH 8.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.7%
CVE-2022-29128 HIGH 8.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.7%
CVE-2020-1507 HIGH 7.9 microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.</p> <p>To exploit the vulnerabi 2.7%