56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-8600 | MED 6.1 | microsoft azure_app_service_on_azure_stack A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App. | 2.3% | — |
| CVE-2022-29139 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-23294 | HIGH 8.8 | microsoft windows_10 Windows Event Tracing Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28477 | HIGH 7.0 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2024-28913 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-35824 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2018-8427 | MED 5.5 | microsoft excel_viewer An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Office | 2.3% | — |
| CVE-2025-54916 | HIGH 7.8 | microsoft windows_10_1507 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 2.3% | — |
| CVE-2024-29055 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 2.3% | — |
| CVE-2024-29054 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 2.3% | — |
| CVE-2024-21324 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 2.3% | — |
| CVE-2019-0817 | MED 5.4 | microsoft exchange_server A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0858. | 2.3% | — |
| CVE-2025-59516 | HIGH 7.8 | microsoft windows_10_1809 Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. | 2.3% | — |
| CVE-2024-30036 | MED 6.5 | microsoft windows_server_2008 Windows Deployment Services Information Disclosure Vulnerability | 2.3% | — |
| CVE-2013-3172 | MED 4.9 | microsoft windows_7 Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to cause a denial of service (system hang) via a | 2.3% | — |
| CVE-2026-49798 | CRIT 9.3 | microsoft windows_10_1607 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 2.3% | — |
| CVE-2019-1357 | MED 4.3 | microsoft edge A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608. | 2.3% | — |
| CVE-2019-0608 | MED 4.3 | microsoft edge A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357. | 2.3% | — |
| CVE-2021-34503 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2025-27469 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | 2.3% | — |
| CVE-2022-24456 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-24453 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-24452 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-23301 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-22007 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |