56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-30153 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2017-11835 | MED 5.5 | microsoft windows_7 Microsoft graphics in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to potentially read data that was not intended to be disclosed due to the way that the Microsoft Windows Embedded OpenType (EOT) font engine parses specially crafted | 2.4% | — |
| CVE-2017-8693 | MED 5.5 | microsoft windows_10 The Microsoft Graphics Component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability in the way it handles objects in memory, aka "Microsoft Graphics Information Disclosure Vulnerability". | 2.4% | — |
| CVE-2020-1103 | MED 6.5 | microsoft sharepoint_enterprise_server An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF). When users are simultaneously logged in to Mic | 2.4% | — |
| CVE-2015-0077 | LOW 2.1 | microsoft windows_7 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize function buffers | 2.4% | — |
| CVE-2022-30208 | MED 6.5 | microsoft windows_10 Windows Security Account Manager (SAM) Denial of Service Vulnerability | 2.4% | — |
| CVE-2022-26913 | HIGH 7.4 | microsoft windows_10 Windows Authentication Information Disclosure Vulnerability | 2.4% | — |
| CVE-2025-27751 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 2.4% | — |
| CVE-2020-23315 | HIGH 7.5 | microsoft chakracore There is an ASSERTION (pFuncBody->GetYieldRegister() == oldYieldRegister) failed in Js::DebugContext::RundownSourcesAndReparse in ChakraCore version 1.12.0.0-beta. | 2.4% | — |
| CVE-2019-0943 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An att | 2.4% | — |
| CVE-2000-0637 | MED 4.6 | microsoft excel Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability. | 2.4% | — |
| CVE-2025-26673 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | 2.4% | — |
| CVE-2023-35639 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2018-8326 | MED 5.4 | microsoft web_customizations A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Open Source Customizatio | 2.4% | — |
| CVE-2025-24052 | HIGH 7.8 | microsoft windows_10_1507 Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumula | 2.4% | — |
| CVE-2019-1402 | MED 5.5 | microsoft office An information disclosure vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Information Disclosure Vulnerability'. | 2.4% | — |
| CVE-2022-26897 | MED 4.9 | microsoft azure_site_recovery Azure Site Recovery Information Disclosure Vulnerability | 2.4% | — |
| CVE-2022-26896 | MED 4.9 | microsoft azure_site_recovery Azure Site Recovery Information Disclosure Vulnerability | 2.4% | — |
| CVE-2021-34521 | HIGH 7.8 | microsoft windows_10 Raw Image Extension Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-33778 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-33777 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-33776 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-33775 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2021-24075 | MED 6.8 | microsoft windows_10 Microsoft Windows VMSwitch Denial of Service Vulnerability | 2.4% | — |
| CVE-2016-3302 | MED 6.3 | microsoft windows_10 Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, when the lock screen is enabled, do not properly restrict the loading of web content, which allows physically proximate attackers to execute arbitrary code via | 2.4% | — |