56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-11830 | MED 5.3 | microsoft windows_10 Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsigned file appear to be signed, due to a security feature bypass, aka "Device Guard Security Feature Bypass Vuln | 2.6% | — |
| CVE-2025-53773 | HIGH 7.8 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally. | 2.6% | — |
| CVE-2023-33134 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2022-22019 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2022-23254 | MED 4.9 | microsoft powerbi-client_js_sdk Microsoft Power BI Information Disclosure Vulnerability | 2.6% | — |
| CVE-2021-31949 | HIGH 7.3 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2026-20820 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 2.6% | — |
| CVE-2018-0864 | MED 5.4 | microsoft sharepoint_server SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure Vulnerability". | 2.6% | — |
| CVE-2024-35264 | HIGH 8.1 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2023-36780 | HIGH 7.2 | microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2015-2382 | LOW 2.1 | microsoft windows_8 win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Win32k Information Dis | 2.6% | — |
| CVE-2015-2381 | LOW 2.1 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Win32k Information Dis | 2.6% | — |
| CVE-2018-8348 | MED 4.7 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 2.6% | — |
| CVE-2019-0992 | MED 4.2 | microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 2.6% | — |
| CVE-2024-21342 | HIGH 7.5 | microsoft windows_11_22h2 Windows DNS Client Denial of Service Vulnerability | 2.6% | — |
| CVE-2018-8207 | MED 4.7 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 2.6% | — |
| CVE-2017-11823 | MED 6.7 | microsoft windows_10 The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it handles Windows PowerShell sessions, aka "Microsoft Windows Security Feature Bypass". | 2.6% | — |
| CVE-2024-30038 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 2.6% | — |
| CVE-2022-23272 | HIGH 8.1 | microsoft dynamics_gp Microsoft Dynamics GP Elevation Of Privilege Vulnerability | 2.5% | — |
| CVE-2022-24508 | HIGH 8.8 | microsoft windows_10 Win32 File Enumeration Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-44707 | MED 6.5 | microsoft windows_10 Windows Kernel Denial of Service Vulnerability | 2.5% | — |
| CVE-2022-21888 | HIGH 7.8 | microsoft windows_10 Windows Modern Execution Server Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-21970 | MED 6.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2.5% | — |
| CVE-2020-1026 | CRIT 9.8 | microsoft research_javascript_cryptography_library A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.An attacker could potentially abuse these bugs to learn information ab | 2.5% | — |
| CVE-2018-8330 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 2.5% | — |