IT
56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.463 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-32030 HIGH 7.5 microsoft .net_framework .NET and Visual Studio Denial of Service Vulnerability 2.2%
CVE-2024-43565 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2.2%
CVE-2024-43562 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2.2%
CVE-2024-43545 HIGH 7.5 microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability 2.2%
CVE-2024-43544 HIGH 7.5 microsoft windows_server_2008 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability 2.2%
CVE-2022-33677 HIGH 7.2 microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability 2.2%
CVE-2022-33633 HIGH 7.2 microsoft lync_server Skype for Business and Lync Remote Code Execution Vulnerability 2.2%
CVE-2021-26422 HIGH 7.2 microsoft lync_server Skype for Business and Lync Remote Code Execution Vulnerability 2.2%
CVE-2021-1719 HIGH 8.0 microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability 2.2%
CVE-2007-5460 MED 4.6 microsoft windows_mobile Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the device, which might make it easier for attackers to decode a PIN/ 2.2%
CVE-2024-26202 HIGH 7.2 microsoft windows_server_2012 DHCP Server Service Remote Code Execution Vulnerability 2.2%
CVE-2024-26195 HIGH 7.2 microsoft windows_server_2008 DHCP Server Service Remote Code Execution Vulnerability 2.2%
CVE-2021-36941 HIGH 7.8 microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability 2.2%
CVE-2020-1523 HIGH 8.9 microsoft sharepoint_server <p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data.</p> <p>To exploit the vulnerability, an attacker 2.2%
CVE-2002-0507 LOW 2.1 microsoft exchange_server An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, 2.2%
CVE-2018-8212 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2.2%
CVE-2017-8486 MED 4.7 microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure due to the way it handles objects in memory, ak 2.2%
CVE-2024-28915 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.2%
CVE-2024-28911 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 2.2%
CVE-2022-24516 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 2.2%
CVE-2022-26785 MED 6.5 microsoft windows_server_2016 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability 2.2%
CVE-2025-21299 HIGH 7.1 microsoft windows_10_1507 Windows Kerberos Security Feature Bypass Vulnerability 2.2%
CVE-2021-42316 HIGH 8.8 microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability 2.2%
CVE-2025-47175 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 2.2%
CVE-2016-3306 HIGH 7.8 microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack sessi 2.2%