56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-29111 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2019-0670 | MED 6.1 | microsoft sharepoint_enterprise_server A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka 'Microsoft SharePoint Spoofing Vulnerability'. | 2.5% | — |
| CVE-2023-36395 | HIGH 7.5 | microsoft windows_server_2008 Windows Deployment Services Denial of Service Vulnerability | 2.5% | — |
| CVE-2023-36392 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability | 2.5% | — |
| CVE-2023-36786 | HIGH 7.2 | microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2024-38146 | HIGH 7.5 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | 2.5% | — |
| CVE-2024-38145 | HIGH 7.5 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | 2.5% | — |
| CVE-2015-2529 | LOW 2.1 | microsoft windows_10 The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability." | 2.5% | — |
| CVE-2021-27055 | HIGH 7.0 | microsoft 365_apps Microsoft Visio Security Feature Bypass Vulnerability | 2.5% | — |
| CVE-2021-34489 | HIGH 7.8 | microsoft windows_10 DirectWrite Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-26900 | HIGH 7.8 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 2.4% | — |
| CVE-2024-43521 | HIGH 7.5 | microsoft windows_server_2012 Windows Hyper-V Denial of Service Vulnerability | 2.4% | — |
| CVE-2021-34492 | HIGH 8.1 | microsoft windows_10 Windows Certificate Spoofing Vulnerability | 2.4% | — |
| CVE-2026-65775 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 2.4% | — |
| CVE-2025-21351 | HIGH 7.5 | microsoft windows_10_1607 Windows Active Directory Domain Services API Denial of Service Vulnerability | 2.4% | — |
| CVE-2024-38233 | HIGH 7.5 | microsoft windows_10_1607 Windows Networking Denial of Service Vulnerability | 2.4% | — |
| CVE-2021-43899 | CRIT 9.8 | microsoft wireless_display_adapter_firmware Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2023-36776 | HIGH 7.0 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 2.4% | — |
| CVE-2020-1066 | HIGH 7.8 | microsoft .net_framework An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The updat | 2.4% | — |
| CVE-2014-4064 | MED 4.9 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly handle use of the paged kernel pool for allocation o | 2.4% | — |
| CVE-2018-8396 | MED 4.7 | microsoft windows_7 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE | 2.4% | — |
| CVE-2020-1528 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Radio Manager API improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted appl | 2.4% | — |
| CVE-2022-26940 | MED 6.5 | microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability | 2.4% | — |
| CVE-2022-22015 | MED 6.5 | microsoft remote_desktop_client Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | 2.4% | — |
| CVE-1999-0376 | MED 4.6 | microsoft windows_nt Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. | 2.4% | — |