56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-0868 | MED 6.1 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f | 2.4% | — |
| CVE-2026-26169 | MED 6.1 | microsoft windows_10_1607 Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally. | 2.4% | — |
| CVE-2004-1649 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in Microsoft Msinfo32.exe might allow local users to execute arbitrary code via a long filename in the msinfo_file command line parameter. NOTE: this issue might not cross security boundaries, so it may be REJECTED in the future. | 2.4% | — |
| CVE-2022-24543 | HIGH 7.8 | microsoft windows_upgrade_assistant Windows Upgrade Assistant Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2020-16939 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>To exploit the vulnerability, an attacker would first hav | 2.4% | — |
| CVE-2022-24520 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2022-24517 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2022-24471 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2022-24470 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2022-24468 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2022-24467 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2025-29810 | HIGH 7.5 | microsoft windows_10_1507 Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network. | 2.4% | — |
| CVE-2024-28936 | HIGH 8.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2024-28934 | HIGH 8.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2024-28933 | HIGH 8.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2024-28932 | HIGH 8.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2024-28931 | HIGH 8.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2024-28909 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2024-28906 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-37705 | CRIT 10.0 | microsoft onefuzz OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable One | 2.4% | — |
| CVE-2016-0014 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges vi | 2.4% | — |
| CVE-2022-23282 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-33781 | HIGH 8.1 | microsoft windows_10 Azure AD Security Feature Bypass Vulnerability | 2.4% | — |
| CVE-2022-21898 | HIGH 7.8 | microsoft windows_10 DirectX Graphics Kernel Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2018-8604 | MED 4.3 | microsoft exchange_server A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server. | 2.4% | — |