56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36579 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.4% | — |
| CVE-2023-36431 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.4% | — |
| CVE-2022-22038 | HIGH 8.1 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-28450 | MED 5.0 | microsoft sharepoint_foundation Microsoft SharePoint Denial of Service Vulnerability | 2.4% | — |
| CVE-2022-23280 | MED 5.3 | microsoft outlook_2016 Microsoft Outlook for Mac Security Feature Bypass Vulnerability | 2.4% | — |
| CVE-2022-24498 | MED 6.5 | microsoft windows_10 Windows iSCSI Target Service Information Disclosure Vulnerability | 2.4% | — |
| CVE-2021-33779 | HIGH 8.1 | microsoft windows_server_2016 Windows AD FS Security Feature Bypass Vulnerability | 2.4% | — |
| CVE-2020-1055 | MED 5.5 | microsoft windows_10 A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs. An un-authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected ADFS s | 2.4% | — |
| CVE-2017-8629 | MED 5.4 | microsoft sharepoint_server Microsoft SharePoint Server 2013 Service Pack 1 allows an elevation of privilege vulnerability when it fails to properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint XSS Vulnerability". | 2.4% | — |
| CVE-2023-36434 | CRIT 9.8 | microsoft windows_10_1507 Windows IIS Server Elevation of Privilege Vulnerability | 2.4% | — |
| CVE-2000-0485 | LOW 2.1 | microsoft sql_server Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability. | 2.4% | — |
| CVE-2017-0082 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0024, CVE-2017-002 | 2.4% | — |
| CVE-2017-0081 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulne | 2.4% | — |
| CVE-2017-0080 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described | 2.4% | — |
| CVE-2017-0079 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Windows 8.1; Windows Server 2012 R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is differe | 2.4% | — |
| CVE-2017-0078 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulne | 2.4% | — |
| CVE-2017-0026 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described | 2.4% | — |
| CVE-2017-0024 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows 10 1607 and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-002 | 2.4% | — |
| CVE-2019-0867 | MED 6.1 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f | 2.4% | — |
| CVE-2008-1453 | HIGH 8.3 | microsoft windows-nt The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically proximate attackers to execute arbitrary code via a large series of Service Discovery Protocol (SDP) packets. | 2.4% | — |
| CVE-2018-0897 | MED 4.7 | microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl | 2.4% | — |
| CVE-2018-0894 | MED 4.7 | microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl | 2.4% | — |
| CVE-2011-1985 | HIGH 7.1 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to g | 2.4% | — |
| CVE-2021-33756 | HIGH 8.8 | microsoft windows_10 Windows DNS Snap-in Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2022-30161 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.4% | — |