IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-0868 MED 6.1 microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f 2.4%
CVE-2026-26169 MED 6.1 microsoft windows_10_1607 Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally. 2.4%
CVE-2004-1649 HIGH 7.2 microsoft windows_2000 Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future. 2.4%
CVE-2022-24543 HIGH 7.8 microsoft windows_upgrade_assistant Windows Upgrade Assistant Remote Code Execution Vulnerability 2.4%
CVE-2020-16939 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit the vulnerability, an attacker would first hav 2.4%
CVE-2022-24520 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.4%
CVE-2022-24517 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.4%
CVE-2022-24471 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.4%
CVE-2022-24470 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.4%
CVE-2022-24468 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.4%
CVE-2022-24467 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability 2.4%
CVE-2025-29810 HIGH 7.5 microsoft windows_10_1507 Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. 2.4%
CVE-2024-28936 HIGH 8.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 2.4%
CVE-2024-28934 HIGH 8.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 2.4%
CVE-2024-28933 HIGH 8.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 2.4%
CVE-2024-28932 HIGH 8.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 2.4%
CVE-2024-28931 HIGH 8.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 2.4%
CVE-2024-28909 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.4%
CVE-2024-28906 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.4%
CVE-2021-37705 CRIT 10.0 microsoft onefuzz OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable One 2.4%
CVE-2016-0014 HIGH 7.8 microsoft windows_10 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges vi 2.4%
CVE-2022-23282 HIGH 7.8 microsoft paint_3d Paint 3D Remote Code Execution Vulnerability 2.4%
CVE-2021-33781 HIGH 8.1 microsoft windows_10 Azure AD Security Feature Bypass Vulnerability 2.4%
CVE-2022-21898 HIGH 7.8 microsoft windows_10 DirectX Graphics Kernel Remote Code Execution Vulnerability 2.4%
CVE-2018-8604 MED 4.3 microsoft exchange_server A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server. 2.4%