56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-26926 | HIGH 7.8 | microsoft windows_10 Windows Address Book Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2023-35643 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Information Disclosure Vulnerability | 2.6% | — |
| CVE-2021-34439 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2019-1073 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1071. | 2.6% | — |
| CVE-2019-1071 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1073. | 2.6% | — |
| CVE-2021-27067 | MED 6.5 | microsoft azure_devops_server Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability | 2.6% | — |
| CVE-2019-1075 | MED 6.1 | microsoft asp.net_core A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. | 2.6% | — |
| CVE-2011-1872 | MED 4.7 | microsoft windows_server_2008 Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malformed machine instructions in a VMBus packet, aka "VMBus Persistent DoS Vulnerability." | 2.6% | — |
| CVE-2021-34464 | HIGH 7.8 | microsoft malware_protection_engine Microsoft Defender Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2019-0881 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows Kernel Elevation of Privilege Vulnerability'. | 2.6% | — |
| CVE-2006-0363 | LOW 2.1 | microsoft msn_messenger The "Remember my Password" feature in MSN Messenger 7.5 stores passwords in an encrypted format under the HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Creds registry key, which might allow local users to obtain the original passwords via a program that cal | 2.6% | — |
| CVE-2018-8141 | MED 4.7 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8127. | 2.6% | — |
| CVE-2022-30172 | MED 5.5 | microsoft office_online_server Microsoft Office Information Disclosure Vulnerability | 2.6% | — |
| CVE-2022-30159 | MED 5.5 | microsoft office_online_server Microsoft Office Information Disclosure Vulnerability | 2.6% | — |
| CVE-2018-8341 | MED 4.7 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows | 2.6% | — |
| CVE-2022-35833 | HIGH 7.5 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 2.6% | — |
| CVE-2021-24083 | HIGH 7.8 | microsoft windows_10 Windows Address Book Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2018-8433 | MED 4.7 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory, aka "Microsoft Graphics Component Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Wi | 2.6% | — |
| CVE-2021-34500 | MED 6.3 | microsoft windows_10 Windows Kernel Memory Information Disclosure Vulnerability | 2.6% | — |
| CVE-2018-0823 | HIGH 7.0 | microsoft windows_10 The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Named Pipe File System handles objects, aka "Named Pipe File System Elevation of Privilege Vulnerability". | 2.6% | — |
| CVE-2018-0822 | HIGH 7.0 | microsoft windows_10 NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way NTFS handles objects, aka "Windows NTFS Global Reparse Point Elevation of Privilege Vulnerabi | 2.6% | — |
| CVE-2026-50423 | HIGH 7.8 | microsoft windows_10_21h2 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. | 2.6% | — |
| CVE-2024-20676 | HIGH 8.0 | microsoft azure_storage_mover Azure Storage Mover Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2021-27092 | MED 6.8 | microsoft windows_10 Azure AD Web Sign-in Security Feature Bypass Vulnerability | 2.6% | — |
| CVE-2016-3310 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl | 2.6% | — |