56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.463 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36414 | HIGH 8.8 | microsoft azure_identity_sdk Azure Identity SDK Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2013-1295 | HIGH 7.2 | microsoft windows_server_2003 The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "CSRSS Memo | 2.2% | — |
| CVE-2022-33649 | CRIT 9.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 2.2% | — |
| CVE-2021-43233 | HIGH 7.5 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-34525 | HIGH 8.8 | microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-34508 | HIGH 8.8 | microsoft windows_10 Windows Kernel Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-35825 | HIGH 8.8 | microsoft visual_studio Visual Studio Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2024-21643 | HIGH 7.1 | microsoft identitymodel_extensions IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable. Mi | 2.2% | — |
| CVE-2016-7300 | HIGH 7.8 | microsoft auto_updater_for_mac Untrusted search path vulnerability in Microsoft Auto Updater for Mac allows local users to gain privileges via a Trojan horse executable file, aka "Microsoft (MAU) Office Elevation of Privilege Vulnerability." | 2.2% | — |
| CVE-2022-21979 | MED 4.8 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 2.2% | — |
| CVE-2025-21311 | CRIT 9.8 | microsoft windows_11_24h2 Windows NTLM V1 Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2024-38149 | HIGH 7.5 | microsoft windows_10_1507 BranchCache Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-38199 | CRIT 9.8 | microsoft windows_10_1507 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2020-1456 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- | 2.2% | — |
| CVE-2004-0115 | MED 4.6 | microsoft virtual_pc VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file. | 2.2% | — |
| CVE-2022-33654 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2016-3372 | MED 6.6 | microsoft windows_server_2008 The kernel API in Microsoft Windows Vista SP2 and Windows Server 2008 SP2 does not properly enforce permissions, which allows local users to spoof processes, spoof inter-process communication, or cause a denial of service via a crafted application, aka "Window | 2.2% | — |
| CVE-2003-0112 | MED 4.6 | microsoft windows_2000 Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger. | 2.2% | — |
| CVE-2023-30846 | CRIT 9.1 | microsoft typed-rest-client typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as fol | 2.2% | — |
| CVE-2021-34534 | MED 6.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-38045 | HIGH 8.8 | microsoft windows_10 Windows Server Service Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2015-2472 | MED 4.3 | microsoft windows_10 Remote Desktop Session Host (RDSH) in Remote Desktop Protocol (RDP) through 8.1 in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not pro | 2.2% | — |
| CVE-2022-35838 | HIGH 7.5 | microsoft windows_11 HTTP V3 Denial of Service Vulnerability | 2.2% | — |
| CVE-2022-35772 | HIGH 7.2 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2023-33141 | HIGH 7.5 | microsoft yet_another_reverse_proxy Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability | 2.2% | — |