56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-33780 | HIGH 8.8 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-28475 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-28473 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-28469 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-28457 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2024-38168 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 2.7% | — |
| CVE-2021-34522 | HIGH 7.8 | microsoft malware_protection_engine Microsoft Defender Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-17040 | MED 6.5 | microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability | 2.7% | — |
| CVE-2019-0757 | MED 6.5 | microsoft .net_core_sdk A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'. | 2.7% | — |
| CVE-2018-8584 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 | 2.7% | — |
| CVE-2010-0233 | HIGH 7.2 | microsoft windows_2000 Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vuln | 2.7% | — |
| CVE-1999-0975 | MED 4.6 | microsoft windows_95 The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed. | 2.7% | — |
| CVE-2015-0058 | HIGH 7.2 | microsoft windows_8.1 Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a crafted application, aka "Windows Cursor Object Double Free Vulnerability." | 2.7% | — |
| CVE-2011-1237 | HIGH 7.2 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 2.7% | — |
| CVE-2021-43908 | MED 4.3 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 2.7% | — |
| CVE-2021-40485 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-24077 | CRIT 9.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-21913 | MED 5.3 | microsoft windows_10 Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass | 2.7% | — |
| CVE-2025-21230 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.7% | — |
| CVE-2007-1209 | HIGH 7.2 | microsoft windows_vista Use-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multi | 2.7% | — |
| CVE-2021-26861 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2014-5711 | MED 5.4 | microsoft microsoft_tech_companion The Microsoft Tech Companion (aka com.technet) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 2.7% | — |
| CVE-2023-38185 | HIGH 8.8 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2021-27047 | HIGH 7.8 | microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2020-17089 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Elevation of Privilege Vulnerability | 2.7% | — |