56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-34727 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-34726 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-34518 | HIGH 7.8 | microsoft excel Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2016-3355 | HIGH 7.8 | microsoft windows_10 The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a | 2.3% | — |
| CVE-2024-28938 | HIGH 8.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2024-28937 | HIGH 8.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2025-59517 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. | 2.3% | — |
| CVE-2024-43541 | HIGH 7.5 | microsoft windows_server_2008 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | 2.3% | — |
| CVE-2001-0373 | LOW 2.1 | microsoft windows_2000 The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information. | 2.3% | — |
| CVE-2001-0261 | LOW 2.1 | microsoft windows_2000 Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files. | 2.3% | — |
| CVE-2024-30010 | HIGH 8.8 | microsoft windows_server_2012 Windows Hyper-V Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2024-49121 | HIGH 7.5 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | 2.3% | — |
| CVE-2018-0761 | MED 5.5 | microsoft windows_7 The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vu | 2.3% | — |
| CVE-2018-0760 | MED 5.5 | microsoft windows_7 The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1, Windows Server 2008 R2, and Windows Server 2012 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Inf | 2.3% | — |
| CVE-2018-0755 | MED 5.5 | microsoft windows_7 The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vu | 2.3% | — |
| CVE-2017-11814 | MED 5.5 | microsoft windows_10 The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an information disclosur | 2.3% | — |
| CVE-2017-11784 | MED 5.5 | microsoft windows_10 The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, allows an information disclosure vulnerability when it improperly handles | 2.3% | — |
| CVE-2017-11765 | MED 5.5 | microsoft windows_10 The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an information disclosur | 2.3% | — |
| CVE-2017-8666 | MED 5.5 | microsoft windows_10 Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to | 2.3% | — |
| CVE-2024-43506 | HIGH 7.5 | microsoft windows_10_1507 BranchCache Denial of Service Vulnerability | 2.3% | — |
| CVE-2021-24070 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-24068 | HIGH 7.8 | microsoft excel Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-24067 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-43896 | MED 5.5 | microsoft powershell Microsoft PowerShell Spoofing Vulnerability | 2.3% | — |
| CVE-2021-40474 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |