56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-8553 | MED 4.7 | microsoft windows_8.1 An information disclosure vulnerability exists in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows Server 2016 when the Windows kernel improperly handles objects in memory, aka "GDI Informa | 2.5% | — |
| CVE-2019-0552 | HIGH 8.8 | microsoft windows_10 An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. | 2.5% | — |
| CVE-2022-26931 | HIGH 7.5 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 2.5% | — |
| CVE-2023-21746 | HIGH 7.8 | microsoft windows_10 Windows NTLM Elevation of Privilege Vulnerability | 2.5% | — |
| CVE-2021-28356 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-28344 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-28340 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-28333 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-28327 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2020-17128 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-24110 | HIGH 7.8 | microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2001-1200 | HIGH 7.2 | microsoft windows_xp Microsoft Windows XP allows local users to bypass a locked screen and run certain programs that are associated with Hot Keys. | 2.5% | — |
| CVE-1999-1259 | LOW 2.1 | microsoft office Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information. | 2.5% | — |
| CVE-2023-23399 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2025-21300 | HIGH 7.5 | microsoft windows_10_1507 Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability | 2.5% | — |
| CVE-2016-3286 | HIGH 7.3 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application | 2.5% | — |
| CVE-2016-3250 | HIGH 7.3 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Server 2012 and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." | 2.5% | — |
| CVE-2016-3249 | HIGH 7.3 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application | 2.5% | — |
| CVE-2022-22042 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 2.5% | — |
| CVE-2021-31967 | HIGH 7.8 | microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-24071 | MED 5.3 | microsoft sharepoint_enterprise_server Microsoft SharePoint Information Disclosure Vulnerability | 2.5% | — |
| CVE-2022-37968 | CRIT 10.0 | microsoft azure_arc-enabled_kubernetes Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kub | 2.5% | — |
| CVE-2022-21977 | LOW 3.3 | microsoft windows_10 Media Foundation Information Disclosure Vulnerability | 2.5% | — |
| CVE-2021-31947 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-31980 | HIGH 8.1 | microsoft intune_management_extension Microsoft Intune Management Extension Remote Code Execution Vulnerability | 2.5% | — |