56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22006 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-31945 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2018-8323 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.3% | — |
| CVE-2018-8299 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.3% | — |
| CVE-2021-36937 | HIGH 7.8 | microsoft windows_10 Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-1722 | HIGH 8.1 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2024-26208 | HIGH 7.2 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28448 | HIGH 7.8 | microsoft visual_studio_code_kubernetes_tools Visual Studio Code Kubernetes Tools Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2026-32178 | HIGH 7.5 | microsoft .net Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network. | 2.3% | — |
| CVE-2018-0754 | MED 5.5 | microsoft windows_10 The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 al | 2.3% | — |
| CVE-2024-43515 | HIGH 7.5 | microsoft windows_10_1507 Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability | 2.3% | — |
| CVE-2022-26784 | MED 6.5 | microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability | 2.3% | — |
| CVE-2022-24538 | MED 6.5 | microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability | 2.3% | — |
| CVE-2022-24457 | HIGH 7.8 | microsoft heif_image_extension HEIF Image Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-24451 | HIGH 7.8 | microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-22709 | HIGH 7.8 | microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-24088 | HIGH 8.8 | microsoft windows_10 Windows Local Spooler Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-38661 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-38660 | HIGH 7.8 | microsoft excel Microsoft Office Graphics Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-38644 | HIGH 7.8 | microsoft mpeg-2_video_extension Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2023-21779 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-34716 | MED 5.9 | microsoft .net .NET Spoofing Vulnerability | 2.3% | — |
| CVE-2022-29115 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-21842 | HIGH 7.8 | microsoft sharepoint_enterprise_server Microsoft Word Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2026-42989 | HIGH 7.8 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. | 2.3% | — |