IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2001-0544 LOW 2.1 microsoft internet_information_services IIS 5.0 allows local users to cause a denial of service (hang) via by installing content that produces a certain invalid MIME Content-Type header, which corrupts the File Type table. 2.4%
CVE-2018-0901 MED 4.7 microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl 2.4%
CVE-2025-60705 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. 2.4%
CVE-2025-21371 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 2.4%
CVE-2021-40476 HIGH 7.5 microsoft windows_10 Windows AppContainer Elevation Of Privilege Vulnerability 2.4%
CVE-2019-1052 MED 4.2 microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 2.4%
CVE-2019-1024 MED 4.2 microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 2.4%
CVE-2019-1003 MED 4.2 microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 2.4%
CVE-2019-0989 MED 4.2 microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 2.4%
CVE-2025-54914 CRIT 10.0 microsoft azure_networking Azure Networking Elevation of Privilege Vulnerability 2.4%
CVE-2024-29985 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.4%
CVE-2024-29984 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.4%
CVE-2024-29983 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.4%
CVE-2024-29982 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.4%
CVE-2024-21386 HIGH 7.5 microsoft asp.net_core .NET Denial of Service Vulnerability 2.4%
CVE-2024-28929 HIGH 8.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 2.4%
CVE-2007-3036 MED 6.9 microsoft windows_2003_server Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain se 2.4%
CVE-2011-4695 MED 6.9 microsoft windows_7 Unspecified vulnerability in Microsoft Windows 7 SP1, when Java is installed, allows local users to bypass Internet Explorer sandbox restrictions and gain privileges via unknown vectors, as demonstrated by the White Phosphorus wp_ie_sandbox_escape module for I 2.4%
CVE-2021-33752 HIGH 8.8 microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability 2.4%
CVE-2021-33750 HIGH 8.8 microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability 2.4%
CVE-2021-33749 HIGH 8.8 microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability 2.4%
CVE-2025-21290 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.4%
CVE-2025-21289 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.4%
CVE-2025-21270 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.4%
CVE-2023-36581 HIGH 7.5 microsoft windows_10 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.4%