IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-36579 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.4%
CVE-2023-36431 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.4%
CVE-2022-22038 HIGH 8.1 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 2.4%
CVE-2021-28450 MED 5.0 microsoft sharepoint_foundation Microsoft SharePoint Denial of Service Vulnerability 2.4%
CVE-2022-23280 MED 5.3 microsoft outlook_2016 Microsoft Outlook for Mac Security Feature Bypass Vulnerability 2.4%
CVE-2022-24498 MED 6.5 microsoft windows_10 Windows iSCSI Target Service Information Disclosure Vulnerability 2.4%
CVE-2021-33779 HIGH 8.1 microsoft windows_server_2016 Windows AD FS Security Feature Bypass Vulnerability 2.4%
CVE-2020-1055 MED 5.5 microsoft windows_10 A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs. An un-authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected ADFS s 2.4%
CVE-2017-8629 MED 5.4 microsoft sharepoint_server Microsoft SharePoint Server 2013 Service Pack 1 allows an elevation of privilege vulnerability when it fails to properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint XSS Vulnerability". 2.4%
CVE-2023-36434 CRIT 9.8 microsoft windows_10_1507 Windows IIS Server Elevation of Privilege Vulnerability 2.4%
CVE-2000-0485 LOW 2.1 microsoft sql_server Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability. 2.4%
CVE-2017-0082 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-002 2.4%
CVE-2017-0081 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulne 2.4%
CVE-2017-0080 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described 2.4%
CVE-2017-0079 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is differe 2.4%
CVE-2017-0078 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulne 2.4%
CVE-2017-0026 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described 2.4%
CVE-2017-0024 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows 10 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-002 2.4%
CVE-2019-0867 MED 6.1 microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f 2.4%
CVE-2008-1453 HIGH 8.3 microsoft windows-nt The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically proximate attackers to execute arbitrary code via a large series of Service Discovery Protocol (SDP) packets. 2.4%
CVE-2018-0897 MED 4.7 microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl 2.4%
CVE-2018-0894 MED 4.7 microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl 2.4%
CVE-2011-1985 HIGH 7.1 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to g 2.4%
CVE-2021-33756 HIGH 8.8 microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability 2.4%
CVE-2022-30161 HIGH 8.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.4%