IT
56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.454 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-30153 HIGH 8.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.4%
CVE-2017-11835 MED 5.5 microsoft windows_7 Microsoft graphics in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to potentially read data that was not intended to be disclosed due to the way that the Microsoft Windows Embedded OpenType (EOT) font engine parses specially crafted 2.4%
CVE-2017-8693 MED 5.5 microsoft windows_10 The Microsoft Graphics Component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability in the way it handles objects in memory, aka "Microsoft Graphics Information Disclosure Vulnerability". 2.4%
CVE-2020-1103 MED 6.5 microsoft sharepoint_enterprise_server An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF). When users are simultaneously logged in to Mic 2.4%
CVE-2015-0077 LOW 2.1 microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize function buffers 2.4%
CVE-2022-30208 MED 6.5 microsoft windows_10 Windows Security Account Manager (SAM) Denial of Service Vulnerability 2.4%
CVE-2022-26913 HIGH 7.4 microsoft windows_10 Windows Authentication Information Disclosure Vulnerability 2.4%
CVE-2025-27751 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 2.4%
CVE-2020-23315 HIGH 7.5 microsoft chakracore There is an ASSERTION (pFuncBody->GetYieldRegister() == oldYieldRegister) failed in Js::DebugContext::RundownSourcesAndReparse in ChakraCore version 1.12.0.0-beta. 2.4%
CVE-2019-0943 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An att 2.4%
CVE-2000-0637 MED 4.6 microsoft excel Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability. 2.4%
CVE-2025-26673 HIGH 7.5 microsoft windows_10_1507 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. 2.4%
CVE-2023-35639 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 2.4%
CVE-2018-8326 MED 5.4 microsoft web_customizations A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Open Source Customizatio 2.4%
CVE-2025-24052 HIGH 7.8 microsoft windows_10_1507 Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumula 2.4%
CVE-2019-1402 MED 5.5 microsoft office An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Information Disclosure Vulnerability'. 2.4%
CVE-2022-26897 MED 4.9 microsoft azure_site_recovery Azure Site Recovery Information Disclosure Vulnerability 2.4%
CVE-2022-26896 MED 4.9 microsoft azure_site_recovery Azure Site Recovery Information Disclosure Vulnerability 2.4%
CVE-2021-34521 HIGH 7.8 microsoft windows_10 Raw Image Extension Remote Code Execution Vulnerability 2.4%
CVE-2021-33778 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.4%
CVE-2021-33777 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.4%
CVE-2021-33776 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.4%
CVE-2021-33775 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.4%
CVE-2021-24075 MED 6.8 microsoft windows_10 Microsoft Windows VMSwitch Denial of Service Vulnerability 2.4%
CVE-2016-3302 MED 6.3 microsoft windows_10 Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, when the lock screen is enabled, do not properly restrict the loading of web content, which allows physically proximate attackers to execute arbitrary code via 2.4%