56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.463 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-21926 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-21844 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2018-8568 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.3% | — |
| CVE-2013-3899 | HIGH 7.2 | microsoft windows_server_2003 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate addresses, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability." | 2.3% | — |
| CVE-2000-0089 | LOW 2.1 | microsoft windows_nt The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability. | 2.3% | — |
| CVE-2023-36764 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability | 2.3% | — |
| CVE-2024-43602 | CRIT 9.9 | microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-31940 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-31192 | HIGH 7.8 | microsoft windows_10 Windows Media Foundation Core Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28470 | HIGH 7.8 | microsoft visual_studio_code_github_pull_requests_and_issues Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28466 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2021-28464 | HIGH 7.8 | microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2018-8431 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 2.3% | — |
| CVE-2018-8426 | MED 5.4 | microsoft sharepoint_enterprise_server_2013 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi | 2.3% | — |
| CVE-2023-36805 | HIGH 7.0 | microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability | 2.3% | — |
| CVE-2022-33678 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-33676 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2019-1334 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1345. | 2.3% | — |
| CVE-1999-0593 | MED 4.9 | microsoft windows_nt The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. | 2.3% | — |
| CVE-2021-24072 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2024-49070 | HIGH 7.4 | microsoft sharepoint_server Microsoft SharePoint Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-33782 | MED 5.5 | microsoft windows_10 Windows Authenticode Spoofing Vulnerability | 2.2% | — |
| CVE-2020-0887 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0877. | 2.2% | — |
| CVE-2011-1870 | HIGH 7.2 | microsoft windows_2003_server Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted a | 2.2% | — |
| CVE-2001-0628 | HIGH 7.2 | microsoft word Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user. | 2.2% | — |