56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38230 | MED 6.5 | microsoft windows_server_2012 Windows Standards-Based Storage Management Service Denial of Service Vulnerability | 2.4% | — |
| CVE-2022-24503 | MED 5.4 | microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability | 2.4% | — |
| CVE-2015-2453 | MED 4.7 | microsoft windows_10 The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive informat | 2.4% | — |
| CVE-2019-0635 | MED 6.2 | microsoft windows_10 An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'. | 2.4% | — |
| CVE-2021-31943 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2019-1170 | HIGH 7.9 | microsoft windows_10 An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. An attacker who successfully exploited the vulnerability could use the sandbox escape to elevate privileges on an affected system. To | 2.4% | — |
| CVE-2023-36720 | HIGH 7.5 | microsoft windows_10_1607 Windows Mixed Reality Developer Tools Denial of Service Vulnerability | 2.4% | — |
| CVE-2023-36703 | HIGH 7.5 | microsoft windows_server_2008 DHCP Server Service Denial of Service Vulnerability | 2.4% | — |
| CVE-2026-45591 | HIGH 7.5 | microsoft .net Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 2.4% | — |
| CVE-2026-42899 | HIGH 7.5 | microsoft .net Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 2.4% | — |
| CVE-2019-0555 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server | 2.4% | — |
| CVE-2023-36789 | HIGH 7.2 | microsoft skype_for_business_server Skype for Business Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2017-8668 | MED 5.5 | microsoft windows_7 The Volume Manager Extension Driver in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2 allows an attacker to run a specially crafted application and obtain kernel information, aka "Volume | 2.4% | — |
| CVE-2022-30209 | HIGH 7.4 | microsoft windows_10 Windows IIS Server Elevation of Privilege Vulnerability | 2.4% | — |
| CVE-2025-21276 | HIGH 7.5 | microsoft windows_10_1507 Windows MapUrlToZone Denial of Service Vulnerability | 2.4% | — |
| CVE-2021-34533 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Font Parsing Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-34530 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2018-0908 | MED 6.1 | microsoft identity_manager Microsoft Identity Manager 2016 SP1 allows an attacker to gain elevated privileges when it does not properly sanitize a specially crafted attribute value being displayed to a user on an affected MIM 2016 server, aka "Microsoft Identity Manager XSS Elevation of | 2.4% | — |
| CVE-2017-8707 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly | 2.4% | — |
| CVE-2017-8706 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper | 2.4% | — |
| CVE-2026-40398 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | 2.4% | — |
| CVE-2024-38015 | HIGH 7.5 | microsoft windows_server_2012 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | 2.4% | — |
| CVE-2021-43882 | CRIT 9.0 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2019-0871 | MED 6.1 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f | 2.4% | — |
| CVE-2019-0870 | MED 6.1 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f | 2.4% | — |